This is a translation provided for convenience. Only the French version is legally binding.

Data Processing Agreement (DPA)

Version applicable during the private beta.

This data processing agreement (the "DPA") is entered into, in accordance with article 28 of the GDPR, between the Client, controller of the web analytics of their sites, and Alexandre Ribes EI (La Boîte à Code), publisher of Quiet Metrics, acting as processor (see the legal notice).

1. Subject matter, duration, nature and purpose of the processing

The processor carries out, on behalf of the Client, the web analytics without any identification or tracking cookie of the sites the Client declares in their account: collection of hits, computation of ephemeral pseudonymous fingerprints, sessionisation, statistical aggregation, and reporting (dashboards, API, reports, exports). The processing lasts as long as the Client's subscription, reversibility included (§ 9).

2. Data processed and data subjects

Data subjects: the visitors of the Client's sites.

Category Detail Persistence
Transient technical data IP address, User-Agent. The fingerprint is not computed on the full address but on the subscriber network: the whole address in IPv4, the /64 prefix alone in IPv6. Never written to the measurement tables. They pass through an encrypted queue, purged every 5 minutes beyond a target TTL of 15 minutes, then a few milliseconds in memory. A definitively failed job may remain encrypted for less than 2 hours before automatic purging.
Pseudonymous fingerprint Salted hash of subscriber network + browser + site (daily rotating salt destroyed after at most 30 hours, specific to the Site's time zone) Detailed events and statistical aggregates kept according to the Client's plan (180 to 760 days); the aggregates contain no personal data
Navigation and acquisition data Page path without query string, referring domain, acquisition channel, UTM parameters extracted before the query string is removed Same
Derived technical and geographical data Country and administrative subdivision (region), browser, operating system, device type, screen class, language. Country and region are derived from the IP address at collection time, never below the subdivision level and without the address itself being kept. Same
Session identifier An opaque value drawn at random when a visit opens, linking together page views separated by less than 30 minutes. It does not allow two visits to be linked. Same
Custom events Names and properties defined by the Client Same
Goals and conversions Goal rules defined by the Client and the corresponding events Same

The Client undertakes not to transmit directly identifying or sensitive data in custom events (Terms of Use, art. 4). The service allows neither cross-site nor cross-day tracking of visitors.

Terminal storage. The collection tools write on the visitor's device no identifier, and no value allowing them to be recognised from one visit to the next. Two values, and only two, may be written there:

  • the opt-out marker qm_ignore, written at the visitor's express request and in order to stop the measurement: a first-party cookie of the Client's site doubled by a local storage entry, lasting 5 years. It is never transmitted to the processor and is not processed by it in any way;
  • the visit continuity cookie qm_visit, written by the measurement so that a network change occurring during a visit does not cause the same person to be counted twice: a first-party cookie of the Client's site, lasting 10 sliding minutes, with no local storage counterpart. Its presence alone, and never its content, is signalled to the processor in order to attach the page view to the visit under way. It is not written on the device of a visitor carrying the opt-out marker, the measurement then being stopped before any write.

Neither of these two values contains an identifier, their content being the same for every visitor. The Client, responsible for the terminal equipment of the visitors to their site, will find the full description in the cookie policy.

3. Documented instructions

The processor processes the data solely on the Client's documented instructions, made up of: this DPA, the Terms of Sale and Terms of Use, and the settings made by the Client in their account (declared sites, exclusions, plan retention, goals, campaigns and custom events). The processor immediately informs the Client if an instruction appears to it to infringe the GDPR or applicable law, and may suspend its execution pending a lawful instruction.

4. Confidentiality and personnel

Any person authorised to process the data is bound by an obligation of confidentiality. Access to production systems is restricted, named and logged.

5. Security (art. 32 GDPR)

The technical and organisational measures are set out in the annex to this DPA.

6. Sub-processing

The Client gives general authorisation for the use of the following sub-processors:

Sub-processor Role Location
OVH SAS Hosting (servers, database, backups) France (EU)

Any change to this list is notified to the Client (email or member area) at least 30 days in advance, with a right to object; where a legitimate objection is not resolved, the Client may terminate with the reversibility of § 9. Sub-processors are bound by obligations equivalent to this DPA; the processor remains fully liable for their performance.

Any AI assistance features or MCP servers of the Service do not process personal data of visitors: they only cover aggregated results and the account holder's messages. The corresponding AI providers therefore do not constitute sub-processors within the meaning of this DPA and are described in the privacy policy.

Three providers appear in the table of § 4 of the privacy policy without constituting sub-processors within the meaning of this DPA, since they do not take part in the web analytics carried out on behalf of the Client: Stripe (payment and billing of the subscription), Proton (email: service messages sent to the account holder, and receipt of contact messages) and Cloudflare (anti-bot protection of the contact and registration forms). The corresponding data is that of the account holder or of a visitor to the quietmetrics.dev site, for which the publisher acts as controller, and not that of the visitors of the Client's sites. The periodic reports carried by Proton contain only aggregated results, free of personal data within the meaning of § 2. Using one of these providers to process data of visitors of the Client's sites would require its prior addition to the table above, subject to the notice period provided for in this article.

7. Assistance to the Client

The processor assists the Client, taking into account the nature of the processing:

  • Data subject rights: the design of the service generally makes the processor unable to identify a visitor (art. 11 GDPR: no identifying data kept, non-reversible fingerprints). It provides the Client with any information useful to answer a request, in particular the public How we count page.
  • Requests received directly: any request manifestly relating to the Client's processing received by Quiet Metrics is passed on to the Client without answering it on the merits, save for a documented instruction or a contrary legal obligation.
  • Impact assessments (DPIA) and prior consultations: technical documentation and cooperation on request.
  • Security: reasonable cooperation in the event of an audit or an incident.

8. Notification of data breaches

The processor notifies the Client of any personal data breach without undue delay and, where possible, within 24 hours of becoming aware of it, at the administrative address of the account and through any emergency channel communicated by the Client. The initial notification may be completed progressively and includes, to the extent available, the nature of the breach, the categories and volumes concerned, the likely consequences, the measures taken or proposed, and a point of contact.

9. Fate of the data at the end of the contract

At the end of the subscription and at the Client's choice:

  • the personal data still held on their behalf is returned to them, or transferred to another designated processor, in a structured, commonly used format, then deleted along with the remaining copies;
  • or it is deleted without prior return.

Unless immediate deletion is requested, the available statistics remain exportable in CSV during a reversibility period of 30 days. API access remains subject to the conditions of the plan, which reserves it for the Pro and Agency plans: it is therefore not guaranteed during reversibility, and CSV export is the route that is. During that period, the Client may request at Protected contact detail: enable JavaScript to reveal it a structured return of the data still held and of the settings of their account. On its expiry, the account data is deleted, subject only to legal retention obligations; data archived for that purpose is isolated and no longer used to provide the Service. A deletion certificate is provided on request. The hashing salts are, in any event, destroyed in accordance with their daily rotation.

10. Audit and documentation

The processor makes available the documentation needed to demonstrate compliance with this DPA (technical documentation, records, description of the measures). The Client may carry out or mandate one audit per 12-month period, at their own cost, on 30 days' notice, on working days, without access to other clients' data and subject to a confidentiality agreement.

11. Records and cooperation with the supervisory authority

The processor keeps the record of categories of processing activities (art. 30.2 GDPR) and cooperates, on request, with the CNIL.


Annex: technical and organisational measures

  • Pseudonymisation at ingestion: fingerprint = hash with a daily secret salt of (subscriber network, browser, site), the subscriber network being the whole address in IPv4 and the /64 prefix alone in IPv6. The day is understood in the Site's time zone, the very one in which its statistics are presented; the salt for a day D is specific to that time zone and destroyed at the latest 6 hours after midnight D+1 in that time zone. Fingerprints then become definitively non-reversible and non-linkable.
  • Encrypted and bounded transit: the IP address and the User-Agent are never written to the measurement tables; the queue payload is encrypted, purged every 5 minutes beyond 15 minutes, and failures are purged in less than 2 hours.
  • Encryption: TLS in transit; site secret keys encrypted at rest; passwords hashed (adaptive algorithm).
  • Partitioning: fingerprints specific to each site (no cross-site linking); data access limited to the owning account (systematic authorisation checks).
  • EU hosting: platform and data hosted in France (OVH). Commercial opening is conditional on encrypted off-server backups and a documented restore test.
  • Access and logging: named production access, least-privilege principle, logging of administrative access.
  • Incident management: escalation procedure, qualification of breaches, keeping of an incident record and contractual notification to the Client.
  • Limitation by design: bounded collection payload (4 KB), cardinality caps, bot filtering, removal of the query string and masking of emails, UUIDs and opaque tokens in URL paths.
  • Bounded retention: daily automatic purging of detailed events and of statistical aggregates beyond the plan's retention; the aggregates are moreover free of personal data.