Legal
Data Processing Agreement
What we do with your visitors' data, what we are not allowed to do with it, and the commitments we make to you as your processor.
Last updated: September 16, 2026
1. What this covers
This Data Processing Agreement (“DPA”) applies when you install the Conversion IQ tag on your website and we process data about your visitors on your behalf. It forms part of our Terms of Service and is entered into between you (the “Controller”) and Conversion IQ, operated by Webtec, Sweden (the “Processor”).
It reflects Article 28 of the UK and EU General Data Protection Regulation. Where this DPA and the Terms conflict on the subject of visitor data, this DPA governs.
2. Roles
You are the controller. It is your website, your visitors, and your decision to install the tag. You decide which pages it runs on and for what purpose.
We are the processor. We process visitor data only on your documented instructions, which for most customers are simply the settings you choose in your dashboard. We do not decide the purposes of that processing.
For your own account data — your name, email, billing details — we are the controller, and our Privacy Policy applies instead.
3. Subject matter, duration and purpose
- Subject matter — measuring how visitors behave on your website so we can find and test improvements to it.
- Duration — for as long as your subscription is active, plus the retention periods in section 7.
- Purpose — conversion analysis, reporting, and running the improvements you approve.
- Categories of data subject — visitors to your website.
4. Categories of data processed
The tag records a deliberately narrow set of data. In full:
- a random session identifier held in
sessionStorage, discarded when the browser tab closes - page address, device type, browser name, screen size and pixel ratio
- page performance measurements (LCP, CLS, INP, TTFB)
- time on page, scroll depth, click count, and the visible labels of elements clicked
- referring URL and UTM campaign parameters
- form engagement: which form was started, whether it completed, how long it took, which field was abandoned
We do not collect IP addresses, cookies, the contents of any form field, session recordings, keystrokes, or any cross-site identifier. Names, email addresses, messages and payment details typed into your forms are never transmitted to us.
Because no direct identifier is collected and the session identifier expires with the browser tab, much of this data is not personal data at all. We treat it as if it were, and hold ourselves to this DPA regardless.
5. Our obligations
- We process visitor data only on your instructions, and only for the purposes in section 3.
- We never sell visitor data, never use it for advertising, and never build profiles of individuals.
- Everyone with access is bound by confidentiality obligations.
- We maintain appropriate technical and organisational security measures (section 8).
- We assist you, so far as we reasonably can, in responding to data subject requests and in meeting your obligations under Articles 32 to 36.
- On termination we delete or return visitor data in accordance with section 7.
6. Aggregated learnings
We derive aggregated, de-identified learnings from how the Service performs across all customers — which kinds of recommendation can be applied to a page, which cannot, and which tend to change the number of enquiries a site receives.
These learnings are statistical. They contain no personal data, no visitor identifiers, and nothing identifying your business, your URLs, your wording or your figures. They are never disclosed to another customer in a form traceable back to you. This is the only use we make of your data beyond serving you directly, and it is described here so that it is explicit rather than assumed.
7. Retention and deletion
- Visitor session data — retained while your subscription is active so your reports can show trends over time.
- On termination — deleted within 30 days of your account closing, together with your account data.
- On request — you can ask us to delete visitor data for your site at any time, and we will do so within 30 days.
- Aggregated learnings — being statistical and containing no personal data, these are not deleted, consistent with section 6.
8. Security
Data is encrypted in transit (TLS) and at rest. Access to production systems is limited to the people who need it and protected by individual credentials. Each customer’s data is partitioned by organisation, and the tag will only accept data from the domains you have authorised, so a key issued for one site cannot record data for another.
9. Subprocessors
You give general authorisation for us to engage the subprocessors listed in our Privacy Policy. We impose data protection obligations on each of them no less protective than those in this DPA, and we remain liable to you for their performance. We will give you reasonable notice before adding a new subprocessor, and you may object on reasonable data protection grounds.
10. International transfers
Some subprocessors are located outside the EEA. Where visitor data is transferred outside the EEA, we rely on the European Commission’s Standard Contractual Clauses.
11. Personal data breaches
If we become aware of a breach affecting visitor data we process for you, we will notify you without undue delay and in any event within 72 hours, with the information you need to meet your own notification obligations.
12. Audits
On reasonable written request, and no more than once a year unless required by a supervisory authority, we will provide the information reasonably necessary to demonstrate our compliance with this DPA.
13. Your responsibilities
You are responsible for having a lawful basis to install the tag and to process your visitors’ data, for telling your visitors about it in your own privacy notice, and for obtaining any consent your jurisdiction requires. We give you the factual detail in section 4 so you can do that accurately.
14. Contact
Questions about this DPA, or a request for a signed copy, go to hello@conversioniq-app.com.