This Data Processing Addendum (“DPA”) forms part of the agreement between Oak Hill Business Consultants LLC, a New Hampshire limited liability company doing business as Core InSites (“Provider”, “we”), the operator of the SiteTraffic.io analytics service (the “Service”), and the customer that accepts it in the Service (“Customer”, “you”). It governs Provider’s processing of personal data on Customer’s behalf in connection with the Service.
Acceptance is recorded electronically in the Service: the accepting user’s account, the version identifier of this document, and a timestamp are stored with Customer’s account records. Each version of this DPA is immutable and permanently available at its versioned URL; material changes are published as a new version and presented for acceptance where required.
For personal data of visitors to Customer’s websites and users of Customer’s digital properties (“Customer Data”), Customer is the controller (or a processor acting for its own clients, in which case Provider is a subprocessor) and Provider is a processor. Provider processes Customer Data only to provide, maintain, secure, and support the Service, and only on Customer’s documented instructions, which are: this DPA, the Service’s settings and configuration chosen by Customer, and Customer’s use of the Service’s features. Provider is an independent controller of its own account, billing, and business records.
When Customer installs the Service’s tracking on a website, the following categories are processed about that site’s visitors: page and referrer URLs, campaign (UTM) parameters, approximate geolocation derived from IP address, device and browser characteristics, screen dimensions, session and engagement events (page views, dwell time, scroll, clicks), and a pseudonymous visitor identifier generated by salted one-way hashing. Raw IP addresses are used transiently for geolocation and abuse prevention and are not stored as part of analytics records.
At Customer’s direction, the Service retrieves reporting data from third-party platform accounts Customer connects — Google Analytics 4 and Google Search Console (via a read-only service account Customer grants), and Meta Page/Instagram insights (via partner access Customer grants). These platforms act under Customer’s own agreements with them; Provider accesses only what Customer authorizes and only to display and analyze it in the Service.
Visitors to Customer’s websites; users of Customer’s connected social properties; Customer’s own personnel who use the Service.
The Service is not designed to process special categories of personal data (Art. 9 GDPR) or data of children, and Customer agrees not to use it to collect such data.
At site setup, Customer declares each site’s audience type, expected jurisdictions (including whether EU traffic is expected), privacy policy location, consent mechanism, and retention period. These declarations are binding processing instructions: Provider and its subprocessors configure collection, consent handling, and retention from them. Customer is responsible for their accuracy and for keeping them current as a site’s audience or legal posture changes, and bears the consequences of processing configured from an inaccurate declaration (see Section 8).
Customer authorizes the subprocessors listed in Annex C. Provider will give at least 30 days’ notice before adding or replacing a subprocessor (posted at the Service’s subprocessor page and/or by email to account administrators). Customer may object on reasonable data-protection grounds within that period; if the objection cannot be resolved, Customer may terminate the affected part of the Service. Provider remains fully liable for its subprocessors’ performance and imposes data-protection terms on them no less protective than this DPA.
Independent-controller carve-out. One exception to the instructions-only rule: the first-party tracking vendor (Merandian LLC) additionally processes limited technical data — security logging and automated traffic/bot classification — as an independent controller for the purpose of protecting its infrastructure and service integrity, under its own data processing terms. This processing is limited to security data (request metadata, classification signals), not Customer’s analytics content, and is disclosed here so Customer can reflect it in its own privacy notices.
Provider and its listed subprocessors process Customer Data in the United States. Where Customer Data originating from the EEA, UK, or Switzerland is transferred to a country without an adequacy decision, the parties rely on the EU Standard Contractual Clauses (Module 2: controller–processor, and Module 3 where Customer is a processor), which are incorporated into this DPA by reference, with the UK Addendum and Swiss adaptations as applicable. Annexes A–C of this DPA serve as the corresponding SCC annexes.
Where the CCPA/CPRA or a similar US state law applies, Provider acts as Customer’s “service provider”/“processor”: Provider does not sell or share Customer Data, does not retain, use, or disclose it outside the direct business relationship or for any purpose other than performing the Service, and certifies that it understands and will comply with these restrictions.
First-party analytics data is retained for the retention period Customer selects for each site at setup, then deleted or irreversibly aggregated. Reporting data retrieved from Customer-connected platforms is cached only as long as needed to serve the Service’s dashboards. Account and billing records are retained as required for Provider’s legal and accounting obligations.
Each party’s liability under this DPA is subject to the limitations of liability in the underlying service agreement. If this DPA conflicts with the underlying agreement, this DPA prevails for data-protection matters. If any provision is held invalid, the remainder stays in effect.
Where a claim, penalty, or vendor liability arises from an inaccurate or outdated declaration made by Customer under Section 2.5 (for example, a site declared “general audience” that is in fact child-directed, or a consent mechanism declared but not actually operating), responsibility for that claim rests with Customer to the extent it results from the inaccurate declaration, and Customer will reimburse Provider for amounts Provider is required to pay its vendors on that basis.
| Subject matter | Web and marketing analytics for Customer’s websites and connected platforms |
|---|---|
| Duration | Term of the Service, plus the deletion window in Section 3.6 |
| Nature and purpose | Collection, aggregation, analysis, and display of visitor traffic and platform reporting data; generation of analytics reports (including, where Customer enables the SEO Intelligence add-on, AI-assisted reports over aggregated data) |
| Categories of data | See Section 2 |
| Data subjects | See Section 2.3 |
| Frequency | Continuous, for the duration of the Service |
| Account access | Customer determines who may access its account. Customer may grant named individuals — including individuals outside Customer’s own organisation, such as its clients or contractors — read-only access limited to the sites Customer specifies. Customer is responsible for whom it grants access to, for the scope of that access, and for revoking it; Provider processes those users’ names and email addresses to operate the account. |
| Subprocessor | Purpose | Location |
|---|---|---|
| Merandian LLC (Mosa.Click) | First-party traffic ingestion and storage | United States |
| Supabase, Inc. | Platform database and user authentication | United States |
| Stripe, Inc. | Subscription billing (Provider does not store payment card data) | United States |
| Anthropic, PBC | AI-assisted report generation over aggregated analytics (only when Customer enables the SEO Intelligence add-on) | United States |
| Maileroo | Transactional email sent at Customer’s request (for example, sending a site’s tracking snippet to a developer Customer nominates); processes the recipient address and the sending user’s name and email address | United States |
Google LLC and Meta Platforms, Inc. are not subprocessors: they process data under Customer’s own agreements with them, and the Service only reads what Customer explicitly authorizes.
Privacy inquiries: privacy@coreinsites.com
Oak Hill Business Consultants LLC d/b/a Core InSites
39 Hot Hole Pond Rd, Concord, New Hampshire 03301, USA