SiteTraffic.io

Data Processing Addendum

Version 2 — Effective August 23, 2026 — canonical URL: app.sitetraffic.io/dpa/v2
Supersedes Version 1 (effective July 31, 2026, amended August 10, 2026), which remains available as the record of what was accepted under it.
What changed in Version 2
· Annex C adds Maileroo (transactional email) as a subprocessor. Added under the Section 4 notice process; Customer’s right to object applies.
· Annex A records that Customer may grant named individuals, including people outside its own organisation, read access to specified sites.
No other section changed.

This Data Processing Addendum (“DPA”) forms part of the agreement between Oak Hill Business Consultants LLC, a New Hampshire limited liability company doing business as Core InSites (“Provider”, “we”), the operator of the SiteTraffic.io analytics service (the “Service”), and the customer that accepts it in the Service (“Customer”, “you”). It governs Provider’s processing of personal data on Customer’s behalf in connection with the Service.

Acceptance is recorded electronically in the Service: the accepting user’s account, the version identifier of this document, and a timestamp are stored with Customer’s account records. Each version of this DPA is immutable and permanently available at its versioned URL; material changes are published as a new version and presented for acceptance where required.

1. Roles and scope

For personal data of visitors to Customer’s websites and users of Customer’s digital properties (“Customer Data”), Customer is the controller (or a processor acting for its own clients, in which case Provider is a subprocessor) and Provider is a processor. Provider processes Customer Data only to provide, maintain, secure, and support the Service, and only on Customer’s documented instructions, which are: this DPA, the Service’s settings and configuration chosen by Customer, and Customer’s use of the Service’s features. Provider is an independent controller of its own account, billing, and business records.

2. What is processed

2.1 First-party site analytics

When Customer installs the Service’s tracking on a website, the following categories are processed about that site’s visitors: page and referrer URLs, campaign (UTM) parameters, approximate geolocation derived from IP address, device and browser characteristics, screen dimensions, session and engagement events (page views, dwell time, scroll, clicks), and a pseudonymous visitor identifier generated by salted one-way hashing. Raw IP addresses are used transiently for geolocation and abuse prevention and are not stored as part of analytics records.

2.2 Data from Customer-authorized platforms

At Customer’s direction, the Service retrieves reporting data from third-party platform accounts Customer connects — Google Analytics 4 and Google Search Console (via a read-only service account Customer grants), and Meta Page/Instagram insights (via partner access Customer grants). These platforms act under Customer’s own agreements with them; Provider accesses only what Customer authorizes and only to display and analyze it in the Service.

2.3 Data subjects

Visitors to Customer’s websites; users of Customer’s connected social properties; Customer’s own personnel who use the Service.

2.4 Special categories

The Service is not designed to process special categories of personal data (Art. 9 GDPR) or data of children, and Customer agrees not to use it to collect such data.

2.5 Customer declarations

At site setup, Customer declares each site’s audience type, expected jurisdictions (including whether EU traffic is expected), privacy policy location, consent mechanism, and retention period. These declarations are binding processing instructions: Provider and its subprocessors configure collection, consent handling, and retention from them. Customer is responsible for their accuracy and for keeping them current as a site’s audience or legal posture changes, and bears the consequences of processing configured from an inaccurate declaration (see Section 8).

3. Provider obligations

  1. Instructions. Process Customer Data only as described in Section 1, unless required otherwise by applicable law (in which case Provider informs Customer before processing, unless the law prohibits it).
  2. Confidentiality. Ensure persons authorized to process Customer Data are bound by confidentiality obligations.
  3. Security. Implement and maintain the technical and organizational measures in Annex B, reviewed and updated as practice evolves, never in a way that materially lowers the protection level.
  4. Breach notice. Notify Customer without undue delay, and in any case within 72 hours of becoming aware of a personal data breach affecting Customer Data, with the information reasonably needed for Customer’s own notification duties.
  5. Assistance. Taking into account the nature of processing, assist Customer with data subject requests (access, erasure, portability, objection) and with Customer’s obligations under Articles 32–36 GDPR and equivalent laws.
  6. Deletion and return. On termination of the Service or on Customer’s written request, delete or return Customer Data within 30 days, except where retention is required by law. Deletion cascades to subprocessors.
  7. Audit. Make available information reasonably necessary to demonstrate compliance with this DPA, and allow audits by Customer or its mandated auditor, no more than once per 12 months on 30 days’ notice (more often after a confirmed breach), during business hours, without access to other customers’ data.

4. Subprocessors

Customer authorizes the subprocessors listed in Annex C. Provider will give at least 30 days’ notice before adding or replacing a subprocessor (posted at the Service’s subprocessor page and/or by email to account administrators). Customer may object on reasonable data-protection grounds within that period; if the objection cannot be resolved, Customer may terminate the affected part of the Service. Provider remains fully liable for its subprocessors’ performance and imposes data-protection terms on them no less protective than this DPA.

Independent-controller carve-out. One exception to the instructions-only rule: the first-party tracking vendor (Merandian LLC) additionally processes limited technical data — security logging and automated traffic/bot classification — as an independent controller for the purpose of protecting its infrastructure and service integrity, under its own data processing terms. This processing is limited to security data (request metadata, classification signals), not Customer’s analytics content, and is disclosed here so Customer can reflect it in its own privacy notices.

5. International transfers

Provider and its listed subprocessors process Customer Data in the United States. Where Customer Data originating from the EEA, UK, or Switzerland is transferred to a country without an adequacy decision, the parties rely on the EU Standard Contractual Clauses (Module 2: controller–processor, and Module 3 where Customer is a processor), which are incorporated into this DPA by reference, with the UK Addendum and Swiss adaptations as applicable. Annexes A–C of this DPA serve as the corresponding SCC annexes.

6. US state privacy laws

Where the CCPA/CPRA or a similar US state law applies, Provider acts as Customer’s “service provider”/“processor”: Provider does not sell or share Customer Data, does not retain, use, or disclose it outside the direct business relationship or for any purpose other than performing the Service, and certifies that it understands and will comply with these restrictions.

7. Retention

First-party analytics data is retained for the retention period Customer selects for each site at setup, then deleted or irreversibly aggregated. Reporting data retrieved from Customer-connected platforms is cached only as long as needed to serve the Service’s dashboards. Account and billing records are retained as required for Provider’s legal and accounting obligations.

8. Liability and order of precedence

Each party’s liability under this DPA is subject to the limitations of liability in the underlying service agreement. If this DPA conflicts with the underlying agreement, this DPA prevails for data-protection matters. If any provision is held invalid, the remainder stays in effect.

Where a claim, penalty, or vendor liability arises from an inaccurate or outdated declaration made by Customer under Section 2.5 (for example, a site declared “general audience” that is in fact child-directed, or a consent mechanism declared but not actually operating), responsibility for that claim rests with Customer to the extent it results from the inaccurate declaration, and Customer will reimburse Provider for amounts Provider is required to pay its vendors on that basis.

Annex A — Processing details

Subject matterWeb and marketing analytics for Customer’s websites and connected platforms
DurationTerm of the Service, plus the deletion window in Section 3.6
Nature and purposeCollection, aggregation, analysis, and display of visitor traffic and platform reporting data; generation of analytics reports (including, where Customer enables the SEO Intelligence add-on, AI-assisted reports over aggregated data)
Categories of dataSee Section 2
Data subjectsSee Section 2.3
FrequencyContinuous, for the duration of the Service
Account accessCustomer determines who may access its account. Customer may grant named individuals — including individuals outside Customer’s own organisation, such as its clients or contractors — read-only access limited to the sites Customer specifies. Customer is responsible for whom it grants access to, for the scope of that access, and for revoking it; Provider processes those users’ names and email addresses to operate the account.

Annex B — Technical and organizational measures

Annex C — Subprocessors

SubprocessorPurposeLocation
Merandian LLC (Mosa.Click)First-party traffic ingestion and storageUnited States
Supabase, Inc.Platform database and user authenticationUnited States
Stripe, Inc.Subscription billing (Provider does not store payment card data)United States
Anthropic, PBCAI-assisted report generation over aggregated analytics (only when Customer enables the SEO Intelligence add-on)United States
MailerooTransactional email sent at Customer’s request (for example, sending a site’s tracking snippet to a developer Customer nominates); processes the recipient address and the sending user’s name and email addressUnited States

Google LLC and Meta Platforms, Inc. are not subprocessors: they process data under Customer’s own agreements with them, and the Service only reads what Customer explicitly authorizes.

Contact

Privacy inquiries: privacy@coreinsites.com
Oak Hill Business Consultants LLC d/b/a Core InSites
39 Hot Hole Pond Rd, Concord, New Hampshire 03301, USA