Data Processing Agreement

Version: 1.0 · Effective: 8 August 2026


1. Parties and how this agreement is entered into

This Data Processing Agreement ("DPA") is between:

  • Processor: Andrei Zhukouski, Żupnicza 16/57, 03-821 Warsaw, Poland — operator of Client Report Autopilot (the "Service"). Contact: reports@azitadvisory.com
  • Controller: the customer who has accepted the Service's Terms of Service ("you").

This DPA forms part of those Terms and applies automatically from the moment you create an account and connect any data. No signature is required for it to take effect. A countersigned copy is available on request to the address above.

Where this DPA conflicts with the Terms of Service on the subject of personal data, this DPA prevails.

2. Definitions

"GDPR" means Regulation (EU) 2016/679. "Controller", "processor", "personal data", "processing", "personal data breach", "data subject" and "supervisory authority" have the meanings given in the GDPR. "Sub-processor" means a third party engaged by the Processor to process personal data on the Controller's behalf. "SCCs" means the standard contractual clauses approved by Commission Implementing Decision (EU) 2021/914.

3. Roles

You are the controller and we are the processor in respect of personal data processed through the Service on your behalf, as described in Annex I.

We act as an independent controller only in respect of your own account and billing information, which is governed by our Privacy Policy, not by this DPA.

If you are yourself a processor acting for another controller — for example where the Analytics property belongs to your own client — you confirm you have that controller's authority to appoint us as a sub-processor on the terms of this DPA.

4. Scope and limits of what is processed

The Service reads aggregated reporting data from Google Analytics: visit and visitor counts, engagement rates, traffic sources and referring domains, landing-page paths, device categories and countries, and daily totals. It does not request or read individual user identifiers, user-level event streams, or advertising audiences.

Much of that aggregated data will not constitute personal data. The personal data most clearly within scope is the recipient email addresses you enter, together with any personal data that happens to appear in a URL path or referrer recorded by your Analytics property. This DPA applies to whatever personal data is in fact processed, and nothing in this section limits your rights if the data proves to contain more than expected.

5. Our obligations as processor

We will:

5.1 Process only on your instructions. We process personal data only to provide the Service as described in Annex I and on your documented instructions. Your instructions are given by your configuration of the Service — the properties you connect, the clients and recipients you enter, the exclusions you set, and your decision to send a report. We will not process personal data for any other purpose, and will never sell it or use it for advertising.

5.2 Tell you if an instruction appears unlawful. If we consider an instruction to infringe the GDPR or other applicable data protection law, we will inform you without undue delay and may suspend that processing until it is resolved.

5.3 Keep it confidential. Any person we authorise to process personal data is bound by a duty of confidentiality and processes it only as needed to perform this DPA.

5.4 Implement security measures. We implement the technical and organisational measures set out in Annex II, appropriate to the risk under Article 32.

5.5 Assist with data subject rights. We will assist you in responding to requests to access, correct, delete, restrict, port or object, taking into account the nature of the processing. Because we hold your data in an account you control, you can satisfy most requests directly through the Service. If a data subject contacts us instead, we will not respond substantively but will refer them to you without undue delay.

5.6 Assist with your wider obligations. We will assist you, taking into account the nature of the processing and the information available to us, with your obligations under Articles 32 to 36 — security, breach notification, data protection impact assessments and prior consultation.

5.7 Notify breaches. We will notify you of a personal data breach affecting your data without undue delay and in any event within 48 hours of becoming aware of it. The notification will describe the nature of the breach, the categories and approximate number of data subjects and records affected so far as known, the likely consequences, and the measures taken or proposed. We will not notify your data subjects or a supervisory authority on your behalf unless you ask us to or the law requires it of us.

5.8 Delete or return data. On termination we will delete personal data processed on your behalf within 30 days, except where we are required by law to keep it — in which case we will keep only what the law requires, for only as long as required, and continue to protect it under this DPA. You can export or delete your data at any time through the Service. On written request within those 30 days we will provide an export before deletion.

5.9 Demonstrate compliance. We will make available the information reasonably necessary to demonstrate compliance with this DPA — see §11 on audits.

6. Automated summary writing

You specifically instruct and authorise us to send the aggregated report figures described in Annex I, together with the business context you write and the client's name and website, to Anthropic for the purpose of generating the report summary. We do not send Anthropic your credentials, Google tokens, recipient email addresses or payment details.

Anthropic processes this data as our sub-processor. Under Anthropic's published policy, inputs and outputs from its commercial API are not used to train its models by default. That default is displaced only where the customer explicitly reports feedback or otherwise opts in; we do not submit Controller data through any such feedback mechanism, so the exception does not arise. Anthropic's Data Processing Addendum, incorporating the SCCs, is automatically part of its Commercial Terms of Service, which we have accepted.

If you do not authorise this processing, you cannot use the Service, because summary writing is its principal function.

7. Sub-processors

7.1 General authorisation. You authorise us to engage the sub-processors listed in Annex III.

7.2 Changes. We will give you at least 30 days' notice before adding or replacing a sub-processor, by email and by updating Annex III at https://reports.azitadvisory.com/dpa.

7.3 Objection. You may object on reasonable data protection grounds within that notice period. We will work with you in good faith to find a solution. If none is available, you may terminate the affected part of the Service and we will refund any fees paid for the unused remainder of your billing period.

7.4 Our responsibility. We impose data protection obligations on each sub-processor no less protective than those in this DPA, and remain responsible to you for their performance.

8. Your obligations as controller

You confirm that:

  • you have a lawful basis for the processing you instruct, and have given any notices and obtained any consents required;
  • you have authority over each Analytics property you connect, and a lawful basis to send reports to each recipient address you enter;
  • your instructions comply with applicable data protection law;
  • you will not enter special category data (Article 9), criminal offence data, payment card numbers, or any personal data not necessary for the Service into free-text fields such as business context or client names. The Service is not designed for such data and Annex II is not calibrated to it.

9. Share links

Reports are reachable at a URL containing a randomly generated token. Anyone holding that URL can view that report. The token is the only access control. You are responsible for who you give it to and for treating it as confidential. We mark share pages as not to be indexed and prevent intermediary caching, but we cannot control onward sharing.

10. Retention

We retain personal data processed on your behalf for as long as your account is active, or until you delete the client or report in question, and then in accordance with §5.8. Disconnecting your Google account immediately revokes our access and deletes our stored tokens.

11. Audits and information

11.1 On reasonable written request, and no more than once in any 12-month period unless a supervisory authority requires otherwise or there has been a personal data breach affecting your data, we will provide the information reasonably necessary to demonstrate compliance with this DPA — including a completed security questionnaire and a written description of our measures.

11.2 Where the law requires an on-site audit, it will be at your cost, on at least 30 days' written notice, at a mutually agreed time, subject to confidentiality, and conducted so as not to disrupt the Service or the data of other customers.

11.3 We are a small operation and do not currently hold ISO 27001 certification or a SOC 2 report. See the note at the end of Annex II. If you require a certified processor, do not rely on this DPA as a substitute.

12. International transfers

We are established in Poland (EU). Some sub-processors are outside the European Economic Area, as marked in Annex III.

Our primary mechanism is the SCCs, for every transfer outside the EEA. Where a sub-processor also holds a valid certification under the EU–US Data Privacy Framework, we treat that as an additional safeguard rather than as the mechanism we depend on. We take this approach deliberately: adequacy findings for US transfers have twice been invalidated (Safe Harbor in 2015, Privacy Shield in 2020), whereas contractual clauses survive such a change. A Controller relying on this DPA therefore does not lose its transfer basis if the Framework's status alters.

Where the SCCs apply they are incorporated into this DPA by reference, with Module Three (processor to processor) applying to onward transfers, Annex I supplying the description of processing, Annex II supplying the technical and organisational measures, and the governing law and forum being those in §16.

We carry out transfer impact assessments where required and will provide a copy of the relevant mechanism on request. The per-sub-processor position is recorded in Annex III with the date it was last verified.

13. Deletion of this agreement's subject matter on request

You may at any time instruct us in writing to delete specific personal data. We will comply within 30 days unless retention is required by law, and confirm completion in writing.

14. Liability

The limitations and exclusions of liability in the Terms of Service apply to this DPA and to the SCCs where incorporated, to the maximum extent permitted by law. Nothing in this DPA limits either party's liability to a data subject under Article 82 GDPR, nor any liability that cannot lawfully be limited.

15. Term

This DPA takes effect when you accept the Terms of Service and continues until we have ceased all processing of personal data on your behalf and completed deletion under §5.8.

16. Governing law

This DPA is governed by the law of Poland, and the courts of Warsaw, Poland have exclusive jurisdiction, save that where the SCCs are incorporated and specify otherwise for the purposes of those clauses, the SCCs prevail on that point.


Annex I — Description of the processing

Subject matter. Provision of the Client Report Autopilot service: reading aggregated website analytics, generating a monthly report with an automatically written summary, and delivering it to recipients nominated by the Controller.

Duration. For the term of the Controller's subscription, plus the deletion period in §5.8.

Nature of the processing. Collection by API, storage, organisation, automated analysis and summary generation, document rendering, transmission by email, provision via a token-protected URL, and erasure.

Purpose. To produce and deliver monthly client performance reports on the Controller's instructions.

Categories of data subjects.

CategoryNotes
Report recipientsIndividuals at the Controller's client whose email addresses the Controller enters
Website visitors of the Controller's clientsOnly in aggregated form; individuals are not identified or identifiable to us in the ordinary case

Types of personal data.

TypeSource
Recipient email addressesEntered by the Controller
Client organisation name and website domainEntered by the Controller
Free-text business contextEntered by the Controller
Aggregated analytics metrics (visits, visitors, engagement, sources, referring domains, landing-page paths, devices, countries, daily totals)Google Analytics, read-only

Special categories of personal data. None. The Controller must not submit them (§8).

Frequency. Continuous while the Controller uses the Service; report generation is typically monthly per client.

Retention. As set out in §10 and §5.8.


Annex II — Technical and organisational measures

These are the measures actually implemented. They are stated factually so a reviewer can verify them.

Access control and authentication

  • Passwords hashed with bcrypt (cost factor 12); plaintext passwords are never stored and cannot be recovered.
  • Login comparison is timing-safe and returns an identical message for an unknown account and a wrong password, so account existence is not disclosed.
  • Sessions use signed, HTTP-only, SameSite=Lax cookies; signatures are verified on every request rather than trusted.

Encryption

  • Google OAuth refresh tokens are encrypted at the application layer with AES-256-GCM, using a key held separately from the database — protection does not rely solely on the database being encrypted at rest.
  • All data in transit is protected with TLS.
  • Data at rest is encrypted by the database and hosting providers (Annex III).

Minimisation by design

  • Google access is requested read-only (analytics.readonly); the Service cannot modify or delete anything in a Controller's Analytics property.
  • The grant is verified to include the expected scope before use, so a partially granted permission fails immediately rather than silently later.
  • Generated PDF documents are not stored. Reports are re-rendered on demand from the stored figures and summary text, reducing the volume of retained data.
  • The AI sub-processor receives aggregated figures and Controller-entered context only — never credentials, tokens, recipient addresses or payment data.

Tenant isolation

  • Every data access is scoped by owner at the query level. A record belonging to another customer and a record that does not exist produce the same result, so existence cannot be probed.
  • Identifiers are validated before reaching the database, so malformed input cannot produce an error that reveals internal structure.

Application security

  • OAuth flows are protected against cross-site request forgery using a single-use, HTTP-only state value compared with a constant-time comparison.
  • All Controller-supplied values are escaped before being rendered into documents; URLs and colour values are format-validated.
  • Free-text business context is passed to the AI sub-processor inside an explicit data boundary and labelled as data rather than instructions.
  • Share tokens are 24 cryptographically random bytes; share responses are marked noindex, nofollow and no-store.

Availability and integrity

  • Report figures are frozen at generation time and never re-queried, so a delivered report's numbers cannot change afterwards.
  • A report already sent cannot be regenerated, preventing figures a recipient has seen from being altered.
  • Database backups are provided by the database sub-processor (Annex III).

Organisational

  • Access to production systems is limited to the Processor personally; there are no other personnel with access.
  • Credentials are held outside the codebase in environment configuration.
  • Sub-processors are chosen with EU hosting where available (see Annex III).

Current limitations — stated honestly

The Processor is a single-person operation. Consequently: there is no segregation of duties; no ISO 27001 certification or SOC 2 report; no independent penetration test has been performed; there is no 24/7 on-call rotation; and formal business continuity and disaster recovery plans rely on the sub-processors' own capabilities rather than independent arrangements. Controllers requiring certified processors or audited controls should take this into account before using the Service.


Annex III — Sub-processors

As at the effective date above.

Sub-processorPurposeLocationOutside EEA?Transfer mechanism
SupabaseDatabase hosting and backupsIreland (eu-west-1)Non/a — EEA
RailwayApplication hosting and report renderingNetherlands (Amsterdam)Non/a — EEA
AnthropicAutomated summary writingUnited StatesYesSCCs (Module 3) via Anthropic's DPA, auto-incorporated into its Commercial Terms; additionally EU–US DPF certified
ResendReport email deliveryUnited StatesYesSCCs via Resend's DPA

Two parties are deliberately absent from this table:

Google is the source of the analytics data, accessed under the permission the Controller grants; it is not our sub-processor for that data.

Paddle.com Market Limited (United Kingdom) sells and bills the subscription as our merchant of record. It processes the Controller's own payment data as an independent controller — not on the Controller's behalf, and it never touches the personal data covered by this DPA (analytics data, recipient addresses, business context). It is therefore outside the scope of this agreement, and is described in our Privacy Policy instead.

Last verified: 6 August 2026. Transfer mechanisms and certifications change; we re-verify this table at least annually and whenever Annex III is amended. DPF certification is recorded above where the provider held it at that date, but per §12 our reliance is on the SCCs in every case, so a change in Framework status does not remove a Controller's transfer basis.

Where a certification is noted, it was confirmed against the provider's own published materials. Controllers requiring independent confirmation should consult the Data Privacy Framework list directly.