Data protection

Data Processing Addendum

Last updated: August 23, 2026

This DPA forms part of the agreement between the customer and Paraito Inc., operator of BetterMeter, when BetterMeter processes personal data on the customer's behalf. It describes the complete current processing model, including optional identity, attribution, integration, and AI features.

1. Scope and roles

The customer is the controller or processor that determines the permitted purpose and configuration. BetterMeter is the processor or subprocessor for customer analytics data and processes it only on documented instructions, including the agreement, product configuration, support requests, and lawful user actions.

Applicable Data Protection Law includes privacy and data-protection law governing the processing, including the GDPR where applicable. If an instruction appears to violate applicable law, BetterMeter will inform the customer unless prohibited from doing so.

2. Processing details

Processing continues for the service term and any limited retention period described below. The purpose is to receive, secure, classify, store, query, display, export, and delete analytics and configuration data and to operate customer-requested integrations and AI-assisted analysis.

  • Data subjects: visitors and users of customer properties, customer personnel, and people represented in customer-connected CRM or advertising records.
  • Event data: query-free URLs and referrers, events, timestamps, campaign data, device and browser data, edge-derived geography, automation signals, and customer-supplied properties.
  • Identifiers and profiles: site-scoped pseudonymous identifiers, optional opaque external IDs, display names, lifecycle stages, visitor properties, and session relationships.
  • Optional data: durable ad click identifiers and _fbp-derived attribution, fingerprint and behavior signals, CRM conversion metadata, ad delivery and creative data, screenshots, and Pulse prompts, tool results, and conversation content.
  • Sensitive data is not intended for the service unless expressly agreed in writing.

3. Customer instructions and duties

  • The customer will provide lawful instructions and an appropriate legal basis and will give required notices and choices to data subjects.
  • The customer will configure optional identify, attribution, fingerprint, behavior, integration, and AI features consistently with applicable law.
  • The customer will not submit data it lacks authority to process and will avoid direct or sensitive identifiers where an opaque value is sufficient.
  • The customer is responsible for responding to data-subject requests as controller; BetterMeter will provide reasonable assistance.

4. Confidentiality and security

Personnel authorized to process customer personal data are bound by confidentiality. BetterMeter maintains technical and organizational measures appropriate to the risk and periodically reviews those measures.

  • TLS for data in transit and provider-managed encryption at rest.
  • Role-based product access, authenticated administrative access, least-privilege practices, and site-scoped authorization.
  • HMAC-SHA-256 pseudonymous identifiers; raw IP addresses are not persisted in analytics storage.
  • Hashed API keys and encrypted customer integration credentials.
  • Query and fragment removal from stored page URLs and referrers, bounded live-event streams, logging controls, backups, monitoring, and incident response.

5. Subprocessors

The customer gives general authorization for subprocessors needed to provide the configured service. Core providers include Vercel, Neon, Upstash, and Vercel Blob. Authentication and communication may use Google, GitHub, and Resend; billing uses Stripe.

Configured features may use OpenRouter and a selected model provider, SerpAPI, DataForSEO, Cloro, Meta, or HubSpot. BetterMeter requires appropriate data-protection obligations from subprocessors and remains responsible for its own obligations under this DPA. We will maintain a current public list and provide notice of material changes through the service or registered account contact where required.

6. International transfers

Customer data may be processed in Canada, the United States, and other locations where an authorized provider operates. BetterMeter will use a lawful transfer mechanism where required, which may include adequacy decisions, the European Commission's Standard Contractual Clauses, or another recognized safeguard.

On request, the parties will complete information reasonably required for the applicable transfer mechanism. Customer configuration and the selected integration determine which transfer routes are used.

7. Rights, assessments, and consultations

Taking into account the nature of processing and information available, BetterMeter will reasonably assist the customer with data-subject requests, security obligations, data-protection impact assessments, and regulator consultations required by applicable law. BetterMeter may require verification and may charge reasonable costs for exceptional assistance beyond standard product capabilities where law permits.

8. Personal-data incidents

BetterMeter will notify the customer without undue delay after confirming a personal-data breach affecting customer data and will provide available information reasonably needed for the customer's assessment and notifications. Notice is not an admission of fault. The customer is responsible for its own regulator and data-subject notifications.

9. Retention, return, and deletion

Event retention follows the customer's active plan: Free 30 days, Starter 365 days, Pro 730 days, and Business without a fixed event-retention limit while active. Other records may follow different operational, contractual, security, tax, or legal periods.

The customer can export account data and can delete an eligible account through settings. Following a verified termination or deletion instruction, BetterMeter will delete or return customer personal data as required by the agreement and applicable law, except data that must be retained or remains temporarily in protected backups, queues, or provider systems subject to controlled expiry.

10. Audit information and controlling terms

BetterMeter will provide information reasonably necessary to demonstrate compliance with this DPA. Audits must protect other customers, security, confidentiality, and service availability; the parties will first use current certifications, reports, policies, and written responses where sufficient.

If this DPA conflicts with the agreement on processing customer personal data, this DPA controls. Mandatory law and an executed transfer mechanism control over inconsistent language. Changes will be posted with a revised date and handled under the agreement's notice terms.

DPA and privacy contact: privacy@bettermeter.com