Legal
Data Processing Agreement
Last updated: September 1, 2026
This Data Processing Agreement (DPA) forms part of the Lumenlytic Terms of Service and governs the processing of personal data on behalf of Customers, including under the GDPR.
1. Definitions
"Controller," "Processor," "Personal Data," "Processing," and "Data Subject" have the meanings given in the EU General Data Protection Regulation (GDPR) and, where applicable, equivalent UK and Swiss legislation. "Customer Data" means any Personal Data processed by Lumenlytic on behalf of the Customer under this Agreement.
2. Roles of the Parties
The Customer is the Controller of Personal Data captured by its analytics implementation (including, where applicable, that of its own website visitors). Lumenlytic (operated by GOD LEVEL TECHNOLOGY (PTY) LTD, trading as Lumenlytic, Hamilton Heights, Brackenfell, Cape Town, South Africa) is a Processor of that data. Each party shall comply with the data protection obligations applicable to its role.
3. Details of Processing
The subject matter, duration, nature, and purpose of the processing, and the categories of data subjects involved, are as follows:
- Purpose: providing cookie-free web analytics (pageviews, referrers, device type, performance metrics) to the Customer.
- Categories of data subjects: visitors to the Customer's websites.
- Categories of personal data: none in identifiable form; Lumenlytic does not collect names, emails, IP addresses in identifiable form, or cookies.
- Duration: for the term of the Customer's subscription, plus any applicable retention period.
4. Processor Obligations
Lumenlytic will process Customer Data only on documented instructions from the Customer, except where required by law (in which case Lumenlytic will inform the Customer unless that notification is legally prohibited). Lumenlytic will ensure that persons authorized to process Customer Data are bound by confidentiality obligations.
5. Data Subject Requests
Lumenlytic will assist the Customer, by appropriate technical and organizational measures and insofar as possible, in fulfilling its obligations to respond to data subject requests. Because the Service does not collect data in identifiable form, such requests will typically relate to Customer account data, which the Customer controls directly.
6. Sub-processors
Lumenlytic may engage sub-processors to provide processing on behalf of the Customer. The Customer generally consents to this engagement. Lumenlytic will ensure that each sub-processor is bound by data protection obligations at least as protective as this Agreement and will notify the Customer of material sub-processor changes.
7. Security
Lumenlytic implements appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including: encrypted transport (TLS), access control and least-privilege for its personnel, rate limiting and bot filtering on its ingest endpoint, and routine security review.
8. Confidentiality
Each party shall keep confidential any non-public information received from the other party in connection with this Agreement, and shall use it only for the purposes of the Agreement.
9. Data Breach
Lumenlytic will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Data, and will provide reasonable information to allow the Customer to meet its own notification obligations. Given the absence of identifiable personal data in the Service, the practical risk of a reportable breach is low.
10. Deletion & Return
On expiry or termination of the Service, and at the Customer's choice, Lumenlytic will delete or return Customer Data, subject to legal retention requirements. Customer Data is deleted in line with the applicable retention period for the Customer's plan.
11. Audit Rights
Where required by the GDPR, the Customer may audit Lumenlytic's compliance with this Agreement, subject to reasonable notice and confidentiality. Lumenlytic may satisfy an audit request by providing certifications, security documentation, or third-party attestations instead of an on-site audit.
12. Liability
Each party's liability under this Agreement is subject to the limitations of liability set out in the Lumenlytic Terms of Service.
13. Governing Law
This Agreement is governed by the same governing law as the Lumenlytic Terms of Service. The provisions of this Agreement take precedence over conflicting provisions in the Terms solely to the extent necessary to comply with data protection law.
14. Contact
For any questions about this Agreement: info@lumenlytic.com.