On this page
- Words used here
- Who does what
- We act only on your instructions
- People with access
- Security
- Subprocessors
- Requests from your visitors
- Helping you meet your obligations
- If there's a breach
- Deleting data
- Audits
- Transfers out of Europe
- US state privacy laws
- Liability and priority
- Annex 1: details of the processing
- Annex 2: security measures
Data Processing Addendum
This addendum is part of the Terms of Service. It covers the personal data Candler processes for you: the visits your websites send to Candler, and the visitor details your team adds. There's nothing to sign. Accepting the terms accepts this. If your company needs a signed copy, email hello@candleranalytics.com.
Words used here.
- Data Protection Laws means the laws that apply to processing Customer Personal Data under the terms, including the EU General Data Protection Regulation 2016/679 ("GDPR"), the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection, and US state privacy laws such as the California Consumer Privacy Act as amended ("CCPA").
- Customer Personal Data means personal data in Customer Data (as the terms define it) that Candler processes for you.
- Subprocessor means a company Candler engages that processes Customer Personal Data.
- Controller, processor, data subject, personal data, processing, personal data breach and supervisory authority have the meanings they have in the GDPR. "Business", "service provider", "sell" and "share" have the meanings they have in the CCPA.
Who does what.
You're the controller of Customer Personal Data and Candler is your processor. If you're a processor yourself, for example an agency running Candler for a client, Candler is your subprocessor, and you'll pass on your controller's instructions and make sure you're allowed to give them. Under US state privacy laws, you're the business and Candler is your service provider or processor. Annex 1 describes the processing.
You're responsible for having a lawful basis for the processing, for the notices and consents your visitors need, and for the accuracy of the data you send. The terms spell this out.
We act only on your instructions.
Candler processes Customer Personal Data only on your documented instructions. Those are the terms, this addendum, your settings in the Service, and what you and your team do in the dashboard and through the API. If we think an instruction breaks Data Protection Laws, we'll tell you. If the law requires us to process Customer Personal Data in some other way, we'll tell you first, unless the law forbids that.
People with access.
Only people who need access to run and support the Service get it, and they're bound by confidentiality. We look at Customer Personal Data only to provide the Service, to fix a problem, to keep the Service secure, when you ask us to, or when the law requires.
Security.
Candler keeps the technical and organizational measures in Annex 2. We may change them over time, but never in a way that lowers the overall level of protection.
Subprocessors.
- You authorize the subprocessors on the subprocessors page.
- Before we add or replace one, we'll update that page and email account owners at least 30 days ahead.
- You can object within those 30 days on reasonable data protection grounds. We'll try to find a fix. If we can't, you can end the affected part of the Service and get back the prepaid time you won't use.
- Each subprocessor is bound by a written contract with data protection terms at least as protective as these. We remain responsible for how they perform.
Requests from your visitors.
The Service gives you tools to answer data subject requests yourself. You can find a visitor by ID or by the details your team entered, export their journey, and delete everything held about them (owners and admins, from the visitor's profile). If a request comes to us directly, we'll pass it to you and won't answer it ourselves, except to say we've done so. If you need more help, we'll give it where we reasonably can.
Helping you meet your obligations.
We'll give you the information you reasonably need for data protection impact assessments and consultations with supervisory authorities, as far as it concerns Candler's processing.
If there's a breach.
If we become aware of a personal data breach affecting Customer Personal Data, we'll tell the account owners without undue delay, and within 48 hours of confirming it. We'll describe what happened, the data and people likely to be affected, the likely consequences and what we're doing about it, and add details as we learn them. We'll take reasonable steps to contain it and limit the harm. Telling you about a breach isn't an admission of fault.
Deleting data.
During the agreement, Customer Personal Data is deleted as your plan and retention settings direct. Those settings are your instructions. When the agreement ends, we delete Customer Personal Data within 30 days, and copies in backups within a further 30 days, unless the law requires us to keep it. Export anything you want to keep before you close your account.
Audits.
On request, we'll give you the information you reasonably need to show that Candler meets this addendum, including answers to a reasonable security questionnaire once a year. If that isn't enough to meet a legal or regulatory requirement, you can audit Candler's processing yourself, or through an independent auditor bound by confidentiality. Audits need 30 days' notice, happen during business hours with as little disruption as possible, no more than once a year unless a supervisory authority requires it or after a breach, and are at your expense.
Transfers out of Europe.
Candler stores Customer Personal Data in Germany. Candler is based in the United States and works on the Service from there, and some subprocessors are US companies. Where the GDPR applies to you and this involves a transfer of Customer Personal Data to a country without an adequacy decision, the Standard Contractual Clauses adopted by the European Commission in Decision (EU) 2021/914 ("SCCs") form part of this addendum, as follows:
- Module Two (controller to processor) applies where you're a controller, and Module Three (processor to processor) where you're a processor. You're the data exporter and Candler is the data importer.
- Clause 7, the docking clause, applies.
- In Clause 9, Option 2 (general written authorization) applies, with the 30 days' notice set out in Subprocessors.
- The optional wording in Clause 11 doesn't apply.
- In Clause 13, the supervisory authority is the one that has authority over you under the GDPR.
- In Clauses 17 and 18, the SCCs are governed by Irish law, and disputes go to the courts of Ireland.
- Annex I of the SCCs is filled in by Annex 1 below, Annex II by Annex 2, and Annex III by the subprocessors page.
United Kingdom. For transfers under the UK GDPR, the International Data Transfer Addendum to the SCCs issued by the UK Information Commissioner (version B1.0) applies. Its Tables 1 to 3 are filled in by this addendum, and either party may end it as set out in its Section 19.
Switzerland. For transfers under Swiss law, the SCCs apply with these changes: the Swiss Federal Data Protection and Information Commissioner is the supervisory authority, references to the GDPR mean the Swiss Federal Act on Data Protection, and data subjects in Switzerland can bring claims where they habitually live.
If the SCCs and this addendum or the terms conflict, the SCCs win.
US state privacy laws.
As your service provider or processor, Candler will not:
- sell or share Customer Personal Data;
- keep, use or disclose it for any purpose other than providing the Service under the terms, or outside our direct business relationship with you;
- combine it with personal data from other sources or other customers, except as the law allows service providers to.
Candler will comply with the CCPA and similar laws as they apply to service providers and processors, give Customer Personal Data the level of protection those laws require, and tell you if it can no longer meet them. You may take reasonable steps to stop and fix any unauthorized use. Candler certifies that it understands and will comply with these restrictions.
Liability and priority.
Each side's liability under this addendum is subject to the limits in the terms, except where Data Protection Laws or the SCCs don't allow them. If this addendum and the terms conflict on data protection, this addendum wins.
Annex 1: details of the processing.
- Subject matter and purpose
- Providing the Service: recording, storing and analyzing visits to your websites, and showing the results to you in the dashboard, exports and API.
- Nature of processing
- Collection, storage, organization, analysis, display, export and deletion.
- Duration
- For the term of the agreement, then until deleted as described in Deleting data.
- Frequency
- Continuous, as visitors use your websites.
- Data subjects
- Visitors to your websites, and your customers whose details your team enters.
- Categories of personal data
- Random visitor and session IDs stored in cookies. Pages viewed, clicks, scrolling and mouse position. Recordings of how pages looked and changed, with form input masked. Device type, browser, operating system, screen size, language, timezone and country. Referring site, campaign tags and ad click ID types. Cart and order events: products, amounts and order number. JavaScript errors. Any name, email, phone number, tags and notes your team adds to a visitor profile. Any properties you send with custom events.
- Sensitive data
- None intended. You must not send special categories of personal data, or the other kinds listed in the Acceptable Use Policy. Form input is masked, and payment card fields are never recorded.
- Retention
- As set by your plan and retention settings. Recordings are kept 14 to 180 days depending on plan.
- Location
- Stored in Nuremberg, Germany. Accessed from the United States.
- Subprocessors
- As listed on the subprocessors page.
Annex 2: security measures.
Collecting less
- Every form field is masked in the visitor's browser before anything is sent. Passwords, emails, phone numbers and fields that look like card numbers, security codes, bank details, tokens, one-time codes, dates of birth or tax IDs stay masked even if a setting would unmask them.
- Payment fields, including Stripe's card fields, are never recorded. Customer detail areas in WooCommerce are masked by default. Account and admin pages aren't tracked by default.
- Sensitive URL parameters, such as tokens, order keys and email addresses, are removed in the browser and again on the server. Things that look like card numbers or email addresses are scrubbed from click labels, error messages and event properties.
- IP addresses aren't stored with visits. Visitors whose browser sends Global Privacy Control aren't tracked, and a consent mode can hold tracking until the visitor agrees.
Access
- Every row of visit data belongs to one website, and every request is checked against the account that owns it. Another account's website looks the same as one that doesn't exist.
- Roles inside an account (owner, admin, analyst, viewer) limit who can change settings, see customer details or delete data.
- Passwords are hashed with scrypt. Sign-ins are rate limited and locked for 15 minutes after five failures. Sign-in sessions expire after 12 idle hours and at most 14 days. Session tokens, reset links, invitations and API keys are stored only as hashes.
- API keys are read-only, rate limited, and never see customer names or visitor profiles.
- Security events are logged with a salted hash of the IP address.
Infrastructure
- All traffic is encrypted with HTTPS. Browser sessions use Secure, HttpOnly, SameSite=Strict cookies, with CSRF tokens and origin checks on every change.
- Servers run in a Hetzner data center in Germany. A network firewall allows only web traffic and administrator access over SSH. SSH accepts keys only, never passwords, and direct root login is off.
- Security updates install automatically.
- The database is backed up every night, and backups are kept for 14 days. Hetzner also keeps daily server backups.
- Replays play back in a sandbox where recorded scripts can't run.
Process
- Retention limits are enforced every hour. Data past its limit is deleted.
- Privacy protections are covered by automated tests that run a real recorder in a real browser and check that typed card numbers, emails, phone numbers and masked details never reach the server.
- Breaches are handled as described in If there's a breach.