Data Processing Addendum
Last updated: 21 September 2026Effective: 21 September 2026Version 1.0
In plain language
This is the Article 28 GDPR agreement that governs our handling of the personal data inside your telemetry. It applies automatically as part of your Terms of Service — you do not have to sign anything to be covered.
You are the controller. We are your processor. We process your data only on your instructions, keep it confidential, secure it with the measures in Annex 2, and delete it when the contract ends.
We name every subprocessor publicly and give you 30 days’ notice before adding one, with a right to object.
Where data leaves the EEA, the 2021 EU Standard Contractual Clauses are incorporated by reference. If your procurement team needs a countersigned PDF, write to [email protected].
This summary is for orientation only. The numbered sections below are the binding text.
1.Parties and how this applies
This Data Processing Addendum (“DPA”) is entered into between:
- Processor
- AtlasAPX Kamil Krawczyk, Poland (address of record: public CEIDG entry for NIP 8291758710), NIP 8291758710 (“TracePath”, “we”)
- Controller
- the customer identified in the account that accepted the Terms of Service (“Customer”, “you”)
- Contact
- [email protected]
This DPA forms part of the Terms of Service (the “Agreement”) and takes effect automatically when you begin using the Service, for as long as we process personal data on your behalf. No separate signature is required for it to bind both Parties.
Note
2.Definitions
“GDPR” means Regulation (EU) 2016/679. “UK GDPR” means the GDPR as retained in the law of the United Kingdom. “Data Protection Law” means the GDPR, the UK GDPR, the Polish Act on the Protection of Personal Data of 10 May 2018, the ePrivacy Directive 2002/58/EC as implemented, and any other privacy or data protection law applicable to a Party’s processing under this DPA.
“Controller”, “Processor”, “Data Subject”, “Personal Data”, “Personal Data Breach”, “Processing” and “Supervisory Authority” have the meanings given in the GDPR.
“Customer Personal Data” means Personal Data contained in Customer Data that TracePath processes on the Customer’s behalf under the Agreement.
“SCCs” means the standard contractual clauses for the transfer of personal data to third countries annexed to Commission Implementing Decision (EU) 2021/914 of 4 June 2021.
“Subprocessor” means any processor engaged by TracePath to process Customer Personal Data.
3.Scope and roles
- For Customer Personal Data, the Customer is the Controller (or a processor acting for a further controller) and TracePath is the Processor (or sub-processor). Each Party complies with the obligations that Data Protection Law places on it in that role.
- The Customer is responsible for the lawfulness of the collection and transmission of Customer Personal Data, for having a valid legal basis, for providing the required privacy information to Data Subjects, and for the accuracy and adequacy of the data it sends. The Customer decides what its applications transmit to the Service.
- TracePath acts as an independent Controller for Account Data, billing data, support correspondence and website data, as described in the Privacy Policy. This DPA does not cover that processing.
- Annex 1 describes the subject matter, duration, nature and purpose of the processing, the categories of Data Subjects and the types of Personal Data, as required by Article 28(3) GDPR.
- Where the Customer is itself a processor acting for one or more further controllers, the Customer warrants that it is authorised to appoint TracePath as a sub-processor on these terms, and that the instructions it gives reflect those of its controllers.
4.Processing on documented instructions
- TracePath processes Customer Personal Data only on the Customer’s documented instructions, including as to transfers to a third country, unless required to do otherwise by Union or Member State law to which TracePath is subject. In that case TracePath informs the Customer of that legal requirement before processing, unless the law prohibits it on important grounds of public interest.
- The Agreement, this DPA, the Documentation, and the configuration the Customer makes in the Service (projects, retention settings, alert rules, monitors, masking options, access controls, API calls) constitute the Customer’s complete documented instructions. Additional or different instructions must be agreed in writing, and TracePath may charge for instructions that require material work beyond the Service as offered.
- TracePath immediately informs the Customer if, in its opinion, an instruction infringes Data Protection Law, and may suspend performance of that instruction until it is confirmed, withdrawn or amended.
- TracePath does not use Customer Personal Data for its own purposes, does not sell it, does not use it to train machine-learning models, and does not use it for advertising or profiling.
5.Confidentiality of personnel
- TracePath ensures that every person authorised to process Customer Personal Data is bound by an appropriate obligation of confidentiality, whether contractual or statutory, that survives the end of their engagement.
- Access is limited to the personnel who need it to provide, secure or support the Service, on a least-privilege basis, and is recorded.
- Personnel receive instruction on their data protection obligations before being granted access to production systems.
6.Security of processing
- TracePath implements and maintains the technical and organisational measures set out in Annex 2, designed to ensure a level of security appropriate to the risk, taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing, as required by Article 32 GDPR.
- TracePath may update those measures over time provided the level of security is not materially reduced. Material reductions are notified in advance.
- The Customer is responsible for the security measures within its own control: the secrecy of its credentials, API tokens and ingest keys, the roles it grants its users, whether it enforces multi-factor authentication, and the masking and scrubbing configuration of its SDKs. Minimising what is sent to the Service is the single most effective control available to the Customer.
7.Subprocessors
- The Customer gives TracePath general written authorisation to engage Subprocessors for the processing described in Annex 1.
- The current Subprocessors are listed on the subprocessors page and reproduced in Annex 3. That page is the authoritative, maintained list.
- TracePath gives at least 30 days’ notice of the intended addition or replacement of a Subprocessor, by email to the address on the Customer’s account. Customers may subscribe to notifications by writing to [email protected].
- The Customer may object on reasonable data-protection grounds within that notice period. The Parties will discuss the objection in good faith. If TracePath cannot provide the Service without the Subprocessor and cannot offer a commercially reasonable alternative, the Customer may terminate the affected part of the Service without penalty, with a pro-rata refund of prepaid fees for the unused remainder of the Billing Period.
- TracePath imposes on each Subprocessor, by written contract, data protection obligations that provide at least the same level of protection as this DPA, including the relevant obligations of Article 28(3) GDPR, and remains fully liable to the Customer for the Subprocessor’s performance.
8.Assistance with data subject rights
- Taking into account the nature of the processing, TracePath assists the Customer by appropriate technical and organisational measures, insofar as possible, in fulfilling the Customer’s obligation to respond to requests to exercise Data Subject rights under Chapter III GDPR.
- The Service itself provides part of the assistance: the Customer can search and inspect data within its own projects through the dashboard, and read it through the documented query API using a personal access token.
- Bulk export of stored telemetry is not yet a self-service function of the Service. TracePath performs it on the Customer’s written instruction to [email protected], within 30 days of the request and at no charge.
- If a Data Subject contacts TracePath directly about Customer Personal Data, TracePath will not respond substantively. It will tell the Data Subject to contact the Customer and, without undue delay, inform the Customer of the request.
- Where the Service does not let the Customer fulfil a request itself, TracePath provides reasonable additional assistance. TracePath may charge a reasonable fee for assistance that requires substantial effort, having first told the Customer what it will cost.
9.Assistance with Articles 32 to 36
Taking into account the nature of processing and the information available to it, TracePath assists the Customer in ensuring compliance with the obligations in Articles 32 to 36 GDPR — security of processing, breach notification to the Supervisory Authority and to Data Subjects, data protection impact assessments, and prior consultation. The information in Annex 1, Annex 2, the subprocessors page and the security page is provided to support the Customer’s own assessment, and is designed to be usable directly in a DPIA.
10.Personal data breach
- TracePath notifies the Customer without undue delay, and in any event within 48 hours, after becoming aware of a Personal Data Breach affecting Customer Personal Data.
- The notification describes, to the extent known: the nature of the breach and, where possible, the categories and approximate number of Data Subjects and records concerned; the likely consequences; the measures taken or proposed to address it and to mitigate its effects; and a contact point for more information. Where the full information is not yet available, it is provided in phases without further undue delay.
- TracePath does not notify a Supervisory Authority or Data Subjects on the Customer’s behalf unless the Customer instructs it to and applicable law permits it. That decision is the Customer’s.
- Notification of an incident is not an admission by TracePath of fault or liability.
- Suspected incidents may be reported to TracePath at any time at [email protected].
11.Return and deletion
- During the Agreement, the Customer can read Customer Personal Data at any time through the dashboard and the documented query API, and can export its dashboard configuration as JSON. A bulk export of stored telemetry is produced by TracePath on written request to [email protected] within 30 days, at no charge.
- On termination, the Customer has 30 days in which to read its data and to request an export. TracePath deletes Customer Personal Data within 60 days after the end of the Agreement, unless Union or Member State law requires it to be stored — in which case TracePath informs the Customer of that requirement and continues to protect the data.
- During the Agreement, telemetry is deleted automatically when the retention period of the Customer’s plan expires; this deletion is enforced by the storage layer.
- On written request, TracePath confirms deletion in writing.
12.Information and audits
- TracePath makes available to the Customer the information necessary to demonstrate compliance with Article 28 GDPR, including this DPA, the security page, the subprocessor list, and reasonable written answers to a security questionnaire.
- The Customer may audit TracePath’s compliance, or mandate an independent auditor to do so, at most once in any twelve-month period, on at least 30 days’ written notice, during normal business hours, without unreasonable disruption, and subject to confidentiality. The Customer may audit more often where a Supervisory Authority requires it or following a confirmed Personal Data Breach affecting its data.
- An audit must not compromise the security or confidentiality of other customers’ data, and does not extend to access to other customers’ Personal Data, to shared infrastructure that cannot be segregated, or to TracePath’s own commercially confidential material.
- TracePath may satisfy an audit request by providing existing documentation and written responses where these reasonably answer the Customer’s questions. TracePath does not currently hold an independent third-party security certification or audit report; if it obtains one it will be offered in place of an on-site audit.
- The Customer bears its own audit costs and TracePath’s reasonable costs of supporting an on-site audit.
13.International transfers and the SCCs
- Customer Personal Data is stored in the European Union. The production infrastructure is operated by Hetzner Online GmbH in Helsinki, Finland (EU).
- Some Subprocessors listed in Annex 3 process Personal Data outside the EEA. For each such transfer, TracePath ensures an appropriate safeguard under Chapter V GDPR is in place.
- Incorporation of the SCCs. Where Data Protection Law requires an appropriate safeguard for a transfer of Customer Personal Data from the EEA and no adequacy decision applies, the SCCs are incorporated into this DPA by reference and apply, completed as follows:
- Module. Module Three (processor to processor) applies where the Customer is a processor; Module Two (controller to processor) applies where the Customer is a controller. Module Four (processor to controller) applies to any transfer from TracePath back to a Customer established outside the EEA.
- Clause 7 (docking). Applies.
- Clause 9 (subprocessors). Option 2, general written authorisation, with the notice period in section 7.3 of this DPA.
- Clause 11 (redress). The optional independent dispute resolution paragraph does not apply.
- Clause 17 (governing law). Option 1, the law of Poland.
- Clause 18(b) (forum). The courts of Poland.
- Annexes. Annex I.A (parties) is completed by section 1 of this DPA; Annex I.B (description of transfer) by Annex 1; Annex I.C (competent supervisory authority) is UODO; Annex II (technical and organisational measures) by Annex 2; Annex III (subprocessors) by Annex 3.
- Where the recipient is certified under the EU–US Data Privacy Framework and the European Commission’s adequacy decision covers the transfer, TracePath may rely on that adequacy decision. TracePath does not rely on it alone: SCCs are maintained in parallel with the relevant Subprocessors so that a valid transfer mechanism survives any suspension or annulment of the adequacy decision.
- For transfers subject to the UK GDPR, the SCCs apply as amended by the UK International Data Transfer Addendum issued by the Information Commissioner. For transfers subject to Swiss law, the SCCs apply with references to the GDPR read as references to the Swiss Federal Act on Data Protection, and the Swiss Federal Data Protection and Information Commissioner as the competent authority.
- If a transfer mechanism is invalidated, the Parties will cooperate in good faith to put an alternative safeguard in place without undue delay. If none is available, the Customer may terminate the affected part of the Service without penalty.
- In the event of a conflict between this DPA and the SCCs, the SCCs prevail for the transfer they govern.
14.Liability and order of precedence
Each Party’s liability under this DPA is subject to the limitations and exclusions in the Agreement, except where Data Protection Law does not permit such limitation — including Article 82 GDPR and Clause 12 of the SCCs, which are not limited by this paragraph as against Data Subjects.
In the event of a conflict, the order of precedence is: the SCCs (for the transfer they govern), then this DPA, then the Agreement.
15.Term
This DPA takes effect when the Customer starts using the Service and remains in force for as long as TracePath processes Customer Personal Data. The obligations in sections 5, 11, 13 and 14 survive its termination.
16.Annex 1 — Description of processing
A. Parties
Data exporter: the Customer, as identified in the account that accepted the Agreement, acting as Controller (or processor for a further controller). Data importer: AtlasAPX Kamil Krawczyk, Poland (address of record: public CEIDG entry for NIP 8291758710), acting as Processor. Contact for both roles: [email protected].
B. Description of the transfer and processing
| Item | Description |
|---|---|
| Subject matter | Provision of the TracePath observability service: ingesting, storing, indexing, querying, visualising and alerting on telemetry submitted by the Customer. |
| Duration | For the term of the Agreement, plus the export and deletion periods in section 11. |
| Nature and purpose | Collection, recording, organisation, structuring, storage, retrieval, consultation, use, transmission (for notifications the Customer configures), restriction and erasure, solely to provide, secure and support the Service. |
| Categories of Data Subjects | Determined by the Customer. Typically: the Customer's end users and customers whose interactions generate telemetry; the Customer's employees, contractors and administrators who use the dashboard; and any individual identifiable from content the Customer's applications emit. |
| Types of Personal Data | Determined by the Customer. Typically: online identifiers (IP address, device and session identifiers, cookie values), user and account identifiers, email addresses and usernames where the Customer includes them, request URLs and parameters, HTTP headers, log message content, exception messages and stack traces, span and resource attributes, session replay recordings of interface content and user interaction, profiling samples, and — where the Customer enables it — AI prompt and completion content. |
| Special categories | None is intended or required. The Customer must not transmit special category data (Article 9), criminal conviction data (Article 10), payment card data or government identifiers as telemetry unless separately agreed in writing with TracePath, including any additional safeguards. |
| Frequency | Continuous, on a streaming basis, for as long as the Customer's systems are instrumented. |
| Retention | Telemetry is deleted automatically when the retention period of the Customer's plan expires. Retention periods per plan are set out in the Terms of Service and on the pricing page. |
| Subprocessors | As listed in Annex 3; processing by each is for the duration of its engagement and limited to the purpose stated there. |
C. Competent supervisory authority
President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych, UODO), ul. Stawki 2, 00-193 Warsaw, Poland.
17.Annex 2 — Technical and organisational measures
The measures below are those actually implemented in the Service. They correspond to the measures described in more detail on the security page, which is maintained alongside this annex. Measures that are not implemented are not listed, and TracePath does not claim certifications it does not hold.
| Area | Measures |
|---|---|
| Pseudonymisation and minimisation | The Customer controls what is transmitted. The SDKs support masking and scrubbing of content before it leaves the Customer's systems, and the Customer chooses retention per plan. TracePath does not enrich telemetry with additional identifiers. |
| Encryption in transit | All connections to the websites, the application, the API and the telemetry endpoint are served over HTTPS with TLS, with certificates managed automatically. HTTP Strict Transport Security is applied. Internal service-to-service traffic runs on a private network not exposed to the internet. |
| Access control — authentication | Passwords are stored only as salted hashes using a deliberately slow hashing function (bcrypt with a work factor of 12 in the application backend; the identity service uses the hashing provided by its authentication framework). Email verification is required before an account becomes usable. Time-based one-time-password two-factor authentication is available, with automatic account lockout after a configured number of failed attempts. Optional single sign-on with Google or GitHub. Cloudflare Turnstile bot protection is applied at sign-up where configured. |
| Access control — sessions and tokens | Dashboard sessions use JSON Web Tokens signed with RSA keys published through a rotating JWKS key set; the signature algorithm and key identifier are pinned, and tokens signed with an unknown key are rejected. Refresh tokens are stored hashed and organised in families so that reuse of a rotated token is detectable. Personal access tokens are stored only as SHA-256 hashes with a non-secret prefix, can carry an expiry, and can be revoked individually. |
| Access control — authorisation | Role-based access control at organisation and project level, enforced by dedicated middleware on every protected route (organisation access, project access, write access, administrative access, operator access). Access to an organisation's data requires membership of that organisation. |
| Tenant isolation | Every data access path is scoped to the requesting organisation. A dedicated automated cross-tenant test suite exercises these paths to verify that one tenant cannot read or write another tenant's data, and runs as part of the backend test suite. |
| Accountability and audit | Administrative actions taken by the Operator are written to an append-only audit table recording the acting account, the action, the target and a timestamp. Sessions created through administrative impersonation are rejected by privileged routes. |
| Availability and resilience | Ingest runs behind an admission-control gate with bounded concurrency; requests that cannot be served are rejected with HTTP 503 and a Retry-After header rather than causing the service to fail. Rate limiting is applied per IP address and per user on authentication, verification, invitation and other sensitive endpoints. Plan quotas bound the resource any single tenant can consume. |
| Network and application hardening | Security response headers are set on application responses: a same-origin Content Security Policy with object-src 'none' and frame-ancestors 'none', X-Content-Type-Options, X-Frame-Options and HSTS. Synthetic monitors in the hosted service are prevented from targeting private, loopback and link-local addresses, so they cannot be used to reach internal infrastructure. Outbound notification and webhook destinations are validated when they are saved and re-validated at dial time, and are refused when they resolve to a private, loopback, link-local or carrier-grade-NAT address. Internal webhooks between services are authenticated with HMAC-SHA256 over a timestamp and the raw body, compared in constant time, with a narrow replay window and a body size cap. |
| Payment data isolation | Payment card data is entered directly into the payment provider's hosted checkout. TracePath's systems never receive or store card numbers. |
| Deletion | Retention is enforced by the storage layer itself through time-to-live policies on telemetry tables, which the storage engine applies in the background, so removal follows expiry within hours rather than to the second. It is supplemented by scheduled cleanup jobs for stored session recordings and expired authentication tokens. Deletion on termination is described in section 11. |
| Data location | Production data is stored in Helsinki, Finland (EU), on infrastructure operated by Hetzner Online GmbH. The provider maintains an ISO/IEC 27001 certified information security management system covering that site. |
| Organisational measures | Least-privilege access to production, limited to the personnel who need it and recorded. Confidentiality obligations for everyone with access. Automated vulnerability scanning of the Go modules behind the backend and the CLI (govulncheck), run daily and on change in continuous integration; the JavaScript dependency trees are not yet covered by automated scanning. Changes to production go through version control and review. A documented process for receiving and acting on security reports at the security mailbox. |
Measures the Customer controls
18.Annex 3 — Subprocessors
These are the subprocessors that process Customer Personal Data contained in telemetry, and they are the ones the change-notification and objection right in section 7 applies to. Providers that only handle account, billing or marketing-website data are processed by TracePath as controller and are outside this DPA (see section 3.3); they are listed, with these, on the subprocessors page, which is the authoritative, maintained list. The table below is a summary as at the date of this DPA.
| Subprocessor | Purpose | Location | Transfer mechanism |
|---|---|---|---|
| Hetzner | Cloud infrastructure: the application servers, PostgreSQL, ClickHouse and object storage that run the Service. | Helsinki, Finland (EU). Provider established in Germany (EU). | No transfer outside the EEA. |
| Cloudflare | Authoritative DNS, CDN and reverse proxy in front of the websites and the API, TLS termination at the edge, WAF and DDoS protection, Turnstile bot protection on sign-up, and email routing for the @tracepath.dev mailboxes. | Global edge network, including locations outside the EEA. | EU Standard Contractual Clauses (Decision 2021/914) under the Cloudflare Customer DPA; Cloudflare also self-certifies under the EU–US Data Privacy Framework. |
| Resend | Transactional email delivery: email verification, password reset, team invitations, alert and on-call notifications, and quota warning emails. | United States. | EU Standard Contractual Clauses under Resend's DPA; Resend also relies on the EU–US Data Privacy Framework. |
19.How to get a signed copy
This DPA is binding without signature. If your procurement or legal team needs an executed document, email [email protected] with your legal entity name, registered address, and the account or organisation it relates to. We will return a countersigned PDF, with the SCCs attached as a standalone annex if you need them that way. There is no charge for this.
TracePath does not offer a Business Associate Agreement and makes no HIPAA offering on any plan. Protected health information must not be transmitted to the Service. See the Acceptable Use Policy.
More legal documents: Legal & trust centre.