Data Processing Agreement Information

Last updated: September 4, 2026

What this page provides

This page explains the data-processing topics relevant to an AttribIQ customer review. It is not an executed Data Processing Agreement and does not replace contract terms approved for a specific customer.

Contact privacy@attribiq.com to ask what contracting documents are currently available and to discuss the processing details required for your use of AttribIQ.

Roles and processing scope

For analytics and revenue data a customer sends about its users, the customer is normally the controller and AttribIQ acts as the processor. The exact roles and instructions must be confirmed in the applicable agreement.

The service processes website and campaign context, project-scoped visitor or session identifiers, custom event data, and payment metadata received through Stripe webhooks or the Payment API. Customers decide which sites, events, and properties they send.

Data minimization and project controls

Customer event properties should not include raw personal data unless it is strictly necessary for the documented purpose. The ingest service removes common sensitive property keys, but a denylist cannot guarantee that customer-supplied properties contain no personal data.

API keys and administration controls are scoped to a project. Deletion and export workflows are also designed around project-level administration; confirm the current workflow and contractual commitments during review.

Hosting, subprocessors, and transfers

AttribIQ is hosted in the European Union. A customer review should still confirm the current locations and providers used for the application, databases, event storage, backups, logs, monitoring, and support access.

The current subprocessor list, transfer safeguards, retention commitments, assistance obligations, deletion terms, and audit provisions must come from the documents supplied for the customer review. They are not established by this overview.