Data Processing Agreement
The Article 28 processor annex for reporte.ai, written to be read by the person who has to approve it.
Last reviewed: September 4, 2026
Data Processing Agreement Sub-processors Legal Notice Refund Policy
See also: Terms Privacy Cookies Terms of AI
What this document is
This is the agreement that governs the personal data we handle on your behalf when you use reporte.ai. It is an annex to the Terms of Service and, on anything about personal data, it wins over them.
It applies from the day you open an account and for as long as we process data for you. You do not have to sign anything for it to apply, and if your legal department wants a signed copy, see the last section.
It is written against the GDPR because that is the framework your legal team will check it against. The company behind reporte.ai is registered in the Dominican Republic and the contract is governed by Dominican law, which does not change the fact that a customer operating in Europe stays under European rules. We would rather say that plainly than let you discover it later.
Who is what
For the data of your own account, we are the controller and our privacy policy explains it. For everything reporte.ai measures on your website and your booking engine, you are the controller and we are the processor. The rest of this document is about that second part.
That means you decide what gets measured and why. You are the one who has to have a lawful basis for measuring your visitors and who has to tell them about it in your own privacy and cookie notice. We give you the tools and the honest description of what they do.
Subject matter, duration, nature and purpose
The four things Article 28 asks to be written down, written down.
- Subject matter: measuring your website and your booking engine, and turning that into reports, alerts and suggestions inside the panel.
- Duration: from the day you open the account until it closes, plus the deletion window described further down.
- Nature of the processing: collection, storage, structuring, aggregation, consultation and deletion, by automated means.
- Purpose: providing the service you contracted. Nothing else. We do not sell the data, we do not share it with other customers and we do not use it to build a product for somebody else.
Categories of data and of data subjects
Data subjects: the visitors of your website and of your booking engine, and the people you invite into your account.
What we record about a visit:
- Page address and title, referrer, campaign parameters, and the time spent on each page.
- Country and city derived from the IP address, device type, browser and operating system.
- Outbound clicks, and the events your site sends us such as form submissions or goal completions.
- The parameters of each booking engine search, meaning check-in and check-out dates, nights, number of people and room type, and each confirmed booking with its amount and currency.
What we never collect:
- Names, email addresses, phone numbers or postal addresses of your guests.
- Payment card data. There is no payment gateway anywhere in the measurement path.
- Special categories of data under Article 9, and data of children as a target.
- Any identifier that follows a person across websites that are not yours.
The IP address is used during the request to work out the country, apply your exclusion rules and stop abuse, and it is not stored. There is an optional per-site setting that stores it for bot detection and troubleshooting. It is switched off on every site in the platform today, and if you switch it on for yours, you are instructing us to store IP addresses on your behalf and you have to say so in your own notice.
Our tracker sets no cookies and reads none, on any site, in any mode. On a site in lightweight mode nothing at all is written to the visitor device. On a site in normal mode the pixel writes one identifier in the browser local storage so a returning visitor is not counted twice. That is storage on a device, so declare it in your own cookie notice, and if you would rather store nothing at all, ask us to move your site to lightweight mode.
What we commit to as processor
- We process only on your documented instructions. Your instructions are this document, the settings you choose in the panel and anything else you ask us in writing.
- If an instruction looks to us like it breaks data protection law, we tell you before carrying it out.
- Everyone with access is bound by confidentiality, and access is granted to the fewest people who need it to do their job.
- We apply the security measures listed in the next section and we keep them at least at that level.
- We help you answer requests from your visitors and, where you need it, with impact assessments and prior consultations.
- We tell you about a personal data breach without undue delay, with what we know at that moment rather than waiting until we know everything.
- We never train a model on your data, we never let anyone else train on it, and we do not send it to a language model provider as part of running the measurement service.
Security measures
What is in place today, described as it is rather than as a list of certifications we do not hold.
- The panel, its database and its backups run on a dedicated server in Nuremberg, Germany, inside the European Union.
- The server exposes no database port and no application port to the internet. Traffic reaches it through an outbound tunnel, and everything travels over TLS.
- The application connects to the database as a limited user with rights over one schema, never as root, and the credentials live outside the code repository with restricted file permissions.
- Account passwords are stored as bcrypt hashes and are never recoverable, by us included.
- Backups run daily and are kept for two weeks. A restore has been tested against a separate database rather than assumed to work, and the backup fails on purpose if the dump comes back smaller than the live schema.
- The event endpoints require either a matching origin or a per-site ingest key, with a rate limit per IP address, so nobody can push invented events into your account with the site id that is public in your HTML.
- When our support needs to see your panel, we use the built-in impersonation, which needs no password of yours, leaves a trace and does not touch your measurement data.
- A daily monitor checks ingestion, the public site and the providers, and it reports every day including when everything is fine, because a watchdog that only speaks on failure cannot be told apart from a dead one.
What we do not claim: we hold no ISO 27001 or SOC 2 certification, and we will not pretend otherwise in a questionnaire. If your procurement requires one, tell us early so nobody wastes a month.
Sub-processors
You give us a general authorisation to use the sub-processors published on our sub-processors page. Each of them is bound by a contract with obligations no weaker than the ones in this document, and we remain responsible to you for what they do.
We announce a new sub-processor at least 30 days before it starts processing anything, and during those 30 days you can object with reasons. If we cannot offer you an alternative that works, you can cancel the affected part of the service without penalty and we return the part of the price you paid and did not use.
To be told of every change, write to [email protected] with the word subprocessors in the subject and we will add you to that notice list.
International transfers
The panel and the database sit in Germany, so the bulk of the data never leaves the European Union. Some sub-processors are outside it, and the country column of the sub-processors table says which ones and under what safeguard, which is either an adequacy decision or the European Commission standard contractual clauses.
Two of them deserve a straight sentence instead of a footnote. Cloudflare is a United States company running a global network, and it sits in front of the panel and holds the booking engine database, so it is on the path of everything. DeepSeek processes in the People's Republic of China and is used only to write content drafts and to judge them, on text from your own public pages and your Search Console queries, never on data about your guests.
If your legal department will not accept a given provider, say so before signing. The AI drafting features can be disabled for your account, and that is a setting rather than a negotiation.
The help you can ask us for
- Requests from your visitors: access, rectification, erasure, restriction, portability and objection. Send us the request and we give you what we hold, or delete it, within ten working days.
- Security of processing, breach notification and impact assessments under Articles 32 to 36, with the information we actually have about our own systems.
- Security questionnaires from your side or questions from a supervisory authority. We answer them ourselves and we do not charge for it.
Deletion and return of the data
While the account is open you can export from the panel at any time, and a Pro account can pull everything through the API without asking us.
When the account closes we keep the measurement data for 30 days, so that coming back or exporting late is still possible, and then we delete it. Backups roll off within two weeks after that. Invoices stay for as long as tax law requires, which is a legal obligation and not a choice. If you want the data deleted immediately instead of after 30 days, ask and we do it.
Audit and information
You can ask us for the information you need to show that we comply, and we will give it. That includes answering your security questionnaire, describing a specific flow and telling you where a given piece of data lives.
You can also audit us, once a year, with 30 days notice, at your cost, and we can ask you to sign a confidentiality agreement first. If a supervisory authority requires more than that, this paragraph is not something we will hide behind.
If something goes wrong
We tell you about a personal data breach as soon as we are aware of it, with the nature of it, the categories and rough number of records involved, what we have done and who to talk to. We send that first message with what we know rather than waiting for a complete picture, and we update it as we learn more.
The notification is a fact, not a judgement about who is at fault, and sending it does not mean we are accepting liability.
Liability, law and changes
The liability limits of the Terms of Service apply to this document too. It is governed by the law of the Dominican Republic, and nothing here removes a right that a mandatory European rule gives you.
If we change this document in a way that affects you, we tell you by email at least 30 days before it takes effect, and the date at the top always says when the text was last reviewed.
How to get it signed
If your legal department needs a signed copy, or would rather we sign their own template, write to [email protected]. We do not charge for it, we do not require your company to be above any size, and we will tell you honestly which clauses of your template we cannot meet instead of signing and hoping.
An honest note to close. This is a template written on what the system actually does, reviewed by the people who built it, and it is not legal advice. Before your legal department signs anything, have a lawyer read it. If a clause here does not match how your company works, write to us and we will discuss it instead of pointing at the page.