Legal

    Data Processing Agreement

    GDPR-compliant data processing terms for Tracking Hippo services.

    Effective Date: 03-08-2026

    Introduction

    A. Controller wishes to use the services of Tracking Hippo and has entered into a contract with Tracking Hippo for that purpose (Agreement), to which Tracking Hippo's Terms of Service and this Data Processing Agreement apply;

    B. Tracking Hippo processes personal data in the performance of the Agreement;

    C. The Parties wish to set forth in writing the terms of the exchange and processing of personal data in this Data Processing Agreement so that the Parties can comply with their respective obligations under the General Data Protection Regulation (GDPR);

    D. This Data Processing Agreement supersedes any previous data processing agreement(s) of similar scope entered into between the Parties.

    1. Definitions

    A number of terms are used in this agreement. The meaning of those terms is clarified below:

    Terms of Service: Tracking Hippo's general terms and conditions governing the use of Services.

    GDPR: The Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and its implementing law.

    Data Subject: The person to whom the Personal Data relates, being an identified or identifiable natural person as referred to in Article 4(1) GDPR.

    Data Breach: A Personal Data Breach as referred to in Article 33 GDPR, being a breach of security leading accidentally or unlawfully to the destruction, loss, alteration or unauthorized disclosure of, or unauthorized access to, Personal Data transmitted, stored or otherwise processed.

    European Economic Area: All countries of the European Union, Liechtenstein, Norway and Iceland.

    Personal Data: Personal data within the meaning of Article 4(1) GDPR.

    Party/Parties: Tracking Hippo or Controller or both parties jointly.

    Sub-processor: Any third party engaged by Tracking Hippo in the processing of Personal Data under the Agreement.

    Agreement: The contract between Tracking Hippo and Controller that relates to the services to be provided by Tracking Hippo to Controller.

    Supervisory Authority: The Belgian Data Protection Authority or any other supervisory authority referred to in the GDPR.

    Processor: FrontLetter BV (trading as Tracking Hippo), having its registered office at Kwadestraat 155 - 5.3, 8800 Roeselare, Belgium, enterprise number 0694.877.811 and VAT number BE0694.877.811.

    Controller: The natural person(s) and/or legal person(s) with whom Tracking Hippo enters into an Agreement.

    Processing: Any act relating to Personal Data as mentioned in Article 4(2) GDPR.

    2. Subject of this Data Processing Agreement

    2.1 Tracking Hippo provides to Controller the services as described in the Agreement. Personal Data are thereby Processed by Tracking Hippo on behalf of the Controller. This Data Processing Agreement applies to any Processing carried out by Tracking Hippo on behalf of the Controller.

    2.2 Controller is 'data controller' within the meaning of the GDPR. Tracking Hippo acts as 'processor' within the meaning of the GDPR.

    2.3 This Data Processing Agreement automatically forms part of the Agreement whenever Tracking Hippo Processes Personal Data on behalf of Controller. No separate signature is required where Controller accepts the Agreement electronically. If this Data Processing Agreement conflicts with the Agreement on the Processing of Personal Data, this Data Processing Agreement prevails.

    2.4 Tracking Hippo acts as an independent controller for Personal Data it Processes for its own account administration, billing, fraud prevention, legal compliance and website operations. Such Processing is governed by Tracking Hippo's Privacy Policy and does not fall within this Data Processing Agreement.

    3. Implementation of Processing

    3.1 Tracking Hippo shall Process Personal Data only on documented instructions from Controller, including instructions provided through account settings, Google server-side Tag Manager container configurations, APIs, support requests and other use of the Services. Tracking Hippo may also Process Personal Data where required by European Union or Member State law and, unless legally prohibited, shall inform Controller of that requirement before Processing.

    3.2 The Personal Data to be Processed under this Data Processing Agreement includes:

    • User identifiers and session data
    • Device and browser information
    • IP addresses and location data
    • Behavioral data (page views, events, interactions)
    • Marketing and advertising identifiers
    • Any other data transmitted through server-side tracking implementation

    3.3 The Processing takes place under the responsibility of Controller. Controller is responsible for the lawfulness, accuracy and scope of the Personal Data and its instructions. Tracking Hippo shall immediately inform Controller if, in its opinion, an instruction infringes the GDPR or other applicable data-protection law.

    3.4 The parties undertake to act at all times in accordance with the GDPR and all related laws and regulations regarding the Processing of Personal Data.

    3.5 Each Party shall maintain the records of Processing activities and documentation required of it under the GDPR.

    3.6 Taking into account the nature of the Processing and the information available to Tracking Hippo, Tracking Hippo shall reasonably assist Controller with Data Subject requests and Controller's obligations under Articles 32 to 36 GDPR, including security, Data Breach notifications, data protection impact assessments and prior consultation with a Supervisory Authority. If Tracking Hippo receives a request directly from a Data Subject concerning Personal Data Processed on behalf of Controller, it shall forward the request to Controller and shall not respond substantively unless instructed or legally required to do so.

    3.7 Tracking Hippo stores and Processes Personal Data for the managed server-side container service only within the European Union. Google server-side Tag Manager containers run in Kubernetes across multiple EU clusters hosted on UpCloud. BunnyWay d.o.o. (bunny.net) hosts the frontend website, application database, DNS and logs on European infrastructure. All service, security and debugging logs are stored within the European Union.

    3.8 Google provides the server-side Tag Manager container software. Tags and third-party destinations configured by Controller are Controller's documented instructions and are not Sub-processors engaged by Tracking Hippo. Controller is responsible for assessing and contracting with those destinations and for any transfers initiated by its container configuration.

    3.9 The subject matter, nature, purpose, categories of Data Subjects, categories of Personal Data, frequency and retention of the Processing are described in Annex I below.

    4. Duration

    4.1 This Data Processing Agreement shall apply until Tracking Hippo no longer Processes Personal Data on behalf of the Controller.

    4.2 After termination of this Data Processing Agreement, the provisions intended for that purpose by their nature shall continue to apply in full.

    4.3 During an active account, service, security, debugging and operational logs are retained for 90 days and then deleted. If Controller deletes its account, the deletion period in Section 11 applies and overrides the ordinary 90-day log-retention period.

    5. Appropriate Technical and Organizational Measures

    5.1 Tracking Hippo shall ensure appropriate (as referred to in Article 32 GDPR) technical and organizational measures so that Personal Data is secured against destruction, loss, unauthorized access, modification or against any form of unlawful processing and to ensure the timely availability of and access to Personal Data.

    5.2 The technical and organizational measures taken by Tracking Hippo include:

    • Encryption of personal data in transit and at rest
    • Access controls and authentication mechanisms
    • Kubernetes-based isolation across multiple clusters hosted in the European Union
    • European hosting for the frontend website, application database, DNS and logs
    • System monitoring and security logging, with logs stored in the European Union
    • Incident response procedures
    • Confidentiality obligations for personnel with authorized access

    5.3 Tracking Hippo may update these measures to reflect technical developments, provided that the overall level of protection is not materially reduced.

    6. Audit Rights

    6.1 Tracking Hippo shall make available the information reasonably necessary to demonstrate compliance with Article 28 GDPR. Controller may audit compliance once per calendar year on reasonable written notice, or more frequently following a confirmed Data Breach or where required by a Supervisory Authority. Audits must avoid disruption and protect the confidentiality and security of other customers. The costs of an audit initiated by Controller shall be borne by Controller unless the audit establishes a material breach by Tracking Hippo.

    7. Data Breaches

    7.1 Tracking Hippo shall notify Controller without undue delay after becoming aware of a Data Breach affecting Personal Data Processed on behalf of Controller. Tracking Hippo shall provide information as it becomes available, including:

    • A. The nature of the Data Breach as well as its (alleged) cause;
    • B. The affected categories of Personal Data and any personal data records in question;
    • C. The contacts from which more information about the Data Breach can be obtained;
    • D. The likely consequences of the Data Breach;
    • E. The measures that Tracking Hippo proposes to take or has taken to remedy the Data Breach, including measures to mitigate any adverse effects thereof.

    7.2 The assessment of whether a Data Breach should be reported to the Supervisory Authority, and any reporting of a Data Breach to the Supervisory Authority, is and shall remain the responsibility of Controller.

    7.3 Tracking Hippo shall properly document each Data Breach, including the facts and findings regarding its consequences and the corrective actions taken. This record shall also include all incidents that are not so serious as to require reporting to the Supervisory Authority.

    8. Secrecy and Confidentiality

    8.1 Tracking Hippo is obliged to keep the Personal Data provided by Controller confidential and to keep it secret, unless Tracking Hippo is required by law or regulation to disclose the Personal Data to third parties.

    8.2 Tracking Hippo shall ensure that persons authorized to Process Personal Data are subject to an appropriate contractual or statutory duty of confidentiality and receive access only where necessary for their responsibilities.

    9. Sub-processors

    9.1 Controller hereby grants Tracking Hippo general permission to engage Sub-processors. Such Sub-processors may have access to the Personal Data to be processed.

    9.2 Tracking Hippo shall give Controller at least 14 days' advance notice of an intended addition or replacement of a Sub-processor. Controller may object within that period on reasonable data-protection grounds. The Parties shall work in good faith to resolve the objection; if no reasonable solution is available, Controller may terminate the affected Service.

    Sub-processorRelevant serviceProcessing activityProvider location
    UpCloud OyTracking Hippo platform and server-side container hostingCloud compute, storage, networking, maintenance, and hosting in selected European data centersFinland; selected EU data centers
    BunnyWay d.o.o. (bunny.net)Frontend website, application database, DNS and logging infrastructureHosting and storage of application data and logs, frontend delivery and authoritative DNSSlovenia; selected EU infrastructure

    9.3 UptimeRobot s. r. o. provides uptime monitoring and Tracking Hippo's public status page. It does not receive Controller website-visitor event payloads or container logs and is therefore an operational provider rather than a Sub-processor for the managed container service.

    9.4 Friendly Captcha GmbH provides EU-based bot and spam protection for Tracking Hippo's own contact, feedback and other protected forms. It does not receive Controller website-visitor event payloads or container logs and is therefore an operational provider rather than a Sub-processor under this Data Processing Agreement.

    9.5 If Tracking Hippo engages a Sub-processor, Tracking Hippo shall impose substantially the same data-protection obligations on that Sub-processor and remains responsible for the Sub-processor's performance of those obligations as required by the GDPR.

    9.6 Provider privacy and data-processing information is available from UpCloud, bunny.net, UptimeRobot, and Friendly Captcha.

    10. Liability

    10.1 If Tracking Hippo fails to fulfill its obligations under this Agreement, the law, other obligations imposed by the Supervisory Authority or obligations related to the foregoing, then Tracking Hippo shall be liable to Controller and/or the Data Subjects for this subject to what is provided in this Data Processing Agreement, the Agreement and the Terms of Service.

    10.2 The liability of Tracking Hippo is limited to what is included in this Data Processing Agreement, the Agreement and the Terms of Service, even if that Agreement and the Terms of Service, for whatever reason, are not or no longer in force.

    10.3 If Controller fails to fulfill its obligations under this Data Processing Agreement and/or otherwise fails to do so or acts in violation of the GDPR and other privacy laws, then Controller shall be liable to Tracking Hippo for this and Controller shall be obligated to compensate Tracking Hippo for any damages incurred as a result.

    10.4 Controller shall indemnify Tracking Hippo against all claims, demands, damages, costs, fines and penalties of third parties, Data Subjects or the Supervisory Authority if Controller fails to comply with the Agreement, this Data Processing Agreement or the Terms of Service or if Controller has not acted in accordance with the GDPR and other privacy laws. Controller shall reimburse all related and resulting costs (including costs of legal assistance) and damages of Tracking Hippo.

    11. Return or Destruction of Personal Data

    11.1 Controller may request an export or deletion of its Personal Data by emailing data@trackinghippo.io. Tracking Hippo may verify the identity and authority of the requester before acting on the request.

    11.2 When Controller deletes its account or the Agreement ends, Tracking Hippo shall delete Controller's Personal Data, containers and logs within 30 days, unless Controller requests an available export before deletion is completed or European Union or Member State law requires retention. Tracking Hippo shall inform Controller of any legally required retention.

    11.3 Once Personal Data has been permanently deleted, it cannot be recovered or exported.

    12. Severability Provision

    12.1 If one or more articles of this Data Processing Agreement should be invalid or otherwise not binding, the validity of the remaining articles of this Data Processing Agreement shall not be affected thereby. In such a case, the Parties shall, in mutual consultation and in the spirit of this Data Processing Agreement, amend the Agreement to the extent necessary. The non-binding articles will be replaced by provisions that differ as little as possible in terms of the Parties' intentions from the non-binding articles in question.

    13. Choice of Law and Forum

    13.1 Belgian law applies to this Data Processing Agreement. The courts of Bruges, Belgium have exclusive jurisdiction to hear disputes between the Parties.

    Annex I — Details of Processing

    Subject matter: Managed hosting and operation of Google server-side Tag Manager containers and the related infrastructure, support, security, debugging and logging services.

    Nature and purpose: Receiving, routing and forwarding event requests according to Controller's container configuration; operating and securing the Services; diagnosing technical problems; preventing abuse; and providing support requested by Controller.

    Duration: For the duration of the Agreement and the deletion period described in Section 11.

    Frequency: Continuous or as initiated by visitors, systems and applications connected by Controller.

    Categories of Data Subjects: Visitors and users of Controller's websites, applications and other digital properties; Controller's customers and prospects; and authorized users and personnel administering the Services.

    Categories of Personal Data: Online and device identifiers, session identifiers, IP addresses, user-agent and browser information, approximate location derived from network data, URLs and referrers, event names, timestamps, interaction and conversion data, marketing identifiers, and other request parameters selected by Controller.

    Special-category data: The Services are not intended to Process special categories of Personal Data or criminal-conviction data. Controller shall not submit such data unless the Processing is lawful, necessary and expressly agreed with Tracking Hippo.

    Retention: Service, security, debugging and operational logs are retained for 90 days during an active account. When an account is deleted or the Agreement ends, Controller's Personal Data, containers and logs are deleted within 30 days, subject only to a legal retention obligation.

    Processing location: European Union only. Containers run in Kubernetes across multiple EU clusters hosted on UpCloud. bunny.net hosts the frontend website, application database, DNS and logs on European infrastructure. All logs are stored in the European Union.

    Data Protection Questions?

    Our Data Protection Officer is available for questions about data processing, privacy rights, deletion, exports, or this agreement.

    This Data Processing Agreement is effective as of 03-08-2026.