Anonview

GDPR

Data Processing Addendum (DPA)

GDPR summary for customers who entrust analytics data to Anonview.

Roles

The customer is the controller for analytics data collected on their sites. Anonview acts as a processor and processes the data only on the customer's instructions to provide the service.

Nature of processing

Privacy-first audience measurement, live dashboard, aggregated reports, and trend extraction. Data are anonymized: no IPs, no third-party cookies, no input values, no persistent identifiers.

Data categories

  • Anonymized events (type, timestamp, cleaned URL).
  • Truncated text and cleaned referrer.
  • Ephemeral session hash with daily rotation.

Retention period

Retention is defined by the customer (TTL). Data are deleted automatically at expiration. No fixed threshold is imposed by Anonview.

Security measures

  • Encryption in transit (TLS).
  • Role-based access to data.
  • Observability without user payload.

Subprocessors

The list of subprocessors is available on the Subprocessorspage. Any material change is notified to allow customer assessment.

GDPR assistance

Anonview assists the customer with data subject requests, incident notifications, and security audits within the limits of available information. Because the data are anonymized, re-identification is not possible.

Custom DPA (Enterprise)

Enterprise customers can request a custom DPA aligned with their internal legal requirements. The custom workflow is handled outside of analytics storage, with no user payload kept in Anonview systems.

Contact legal for a custom DPA