Version 1.0 · Effective May 28, 2026
Between: You (the Controller) and Marketist (the Processor)
This DPA forms part of your Marketist Terms of Service and governs the processing of personal data under GDPR Article 28. By using Marketist, you accept this DPA.
Parties
Controller
You, the registered Marketist user / organization (“Controller”)
Processor
Marketist, Frankfurt am Main, Germany (“Processor”)
This Data Processing Agreement (“DPA”) governs the processing of personal data by Marketist (Processor) on behalf of the Controller in connection with the provision of web analytics services under GDPR Article 28.
Processing begins when the Controller first uses the Marketist tracker and continues until the Controller deletes their account or otherwise terminates the relationship. Data is deleted within 30 days of termination.
Marketist processes data to provide aggregate web analytics — counting page views, sessions, traffic sources, and conversion events — on behalf of the Controller. No individual visitor profiles are created.
Effectively none.Marketist's tracker is designed to operate without collecting personally identifiable information:
The only data processed is aggregated behavioral metrics (page URLs, referrer domains, UTM parameters, browser type categories, anonymous country-level geography).
Visitors to the Controller's website(s). No direct relationship exists between Marketist and these individuals.
Marketist commits to:
The Controller grants general authorisation to use the following sub-processors. Marketist will notify the Controller of changes at least 30 days in advance.
| Sub-processor | Role | Location |
|---|---|---|
| Supabase | Database storage | Frankfurt, EU |
| Vercel | Hosting & edge functions | EU Edge Network |
| Cloudflare | CDN & edge computing | Global (EU nodes) |
| Resend | Transactional email delivery | EU |
Data is primarily processed within the EU/EEA. Cloudflare may route traffic globally for performance, but analytics data at rest is stored within the EU. All transfers comply with Chapter V GDPR (Standard Contractual Clauses where applicable).
Marketist implements the following technical and organisational measures:
The Controller may request evidence of compliance once per calendar year at no charge, including copies of relevant certifications (e.g., SOC 2 reports from sub-processors) and responses to compliance questionnaires.
On-site audits may be agreed in writing with at least 30 days notice, at the Controller's expense.
Upon account deletion or termination of services, Marketist will delete all personal data within 30 days, except where retention is required by applicable law. A deletion confirmation will be provided on request.