Legal

Data Processing Agreement

How ClickClacks processes your visitors' personal data on your behalf.

Last updated: [Effective date]

1. Parties and scope

This agreement is between K3 Technologies, Las Vegas, Nevada, United States ("ClickClacks") and the customer that has accepted the Terms of Service ("Customer"). It covers the personal data ClickClacks processes for the Customer to provide the Service, for as long as the Service is provided and until that data is deleted afterwards.

The Customer is the controller of that data, or a processor for its own clients. ClickClacks is the Customer's processor, and its service provider under the CCPA.

2. Instructions

ClickClacks processes Customer personal data only on the Customer's documented instructions: this agreement, the Terms of Service and the Customer's configuration of the Service. If the law requires other processing, ClickClacks tells the Customer first unless the law forbids it. ClickClacks tells the Customer if it believes an instruction breaks data protection law.

ClickClacks does not sell Customer personal data, share it for cross-context behavioral advertising, or use it for any purpose other than providing the Service.

3. Confidentiality

Only people who need access to provide the Service have it, and they are bound to confidentiality.

4. Security

ClickClacks applies the measures in Annex B and keeps them at least as protective for the life of this agreement.

5. Subprocessors

The Customer authorizes the subprocessors listed on the subprocessors page. ClickClacks binds each one to data protection terms no less protective than these and remains responsible for their work. ClickClacks updates the list at least [Notice period, for example 30 days] before a new subprocessor starts. A Customer that objects on reasonable data protection grounds within that time may end the affected Service. [Counsel to confirm the remedy, for example a refund of prepaid fees for the unused period.]

6. Requests from individuals

ClickClacks helps the Customer answer requests from individuals to see, correct, erase, restrict or object to the use of their data, and acts on the Customer's request without undue delay so the Customer can meet its own deadline. Today the Customer finds a person and exports their events in the application, and asks ClickClacks to erase or restrict one person's data. If an individual writes to ClickClacks directly about Customer data, ClickClacks passes the request to the Customer and does not answer it itself.

7. Personal data breaches

ClickClacks notifies the Customer without undue delay after becoming aware of a personal data breach affecting Customer personal data. The notice describes what happened, the data and people likely affected, the likely consequences and what is being done, and is updated as more becomes known.

8. Assistance

Taking into account the nature of the processing and the information it has, ClickClacks helps the Customer with data protection impact assessments and with consulting regulators.

9. Return and deletion

The Customer can export its data while the Service runs. When the Service ends, ClickClacks deletes Customer personal data, including from its archive, unless the law requires it to be kept. Backups are kept isolated, expire on their normal schedule and are not used for any other purpose; if a backup is restored, deletions are applied again before the data is used.

10. Audits

ClickClacks gives the Customer the information needed to show that this agreement is being met, and allows an audit by the Customer or an auditor it appoints, [Audit frequency, for example at most once a year unless a breach or a regulator requires more], on reasonable notice and subject to confidentiality.

11. International transfers

Where Customer personal data subject to EEA, UK or Swiss law is transferred to a country without an adequacy decision, the parties rely on [Transfer mechanism, for example the European Commission's Standard Contractual Clauses, Module Two, or Module Three where the Customer is a processor, with the UK Addendum and Swiss amendments where they apply]. The annexes below complete them.

12. Annex A: The processing

Subject matterProduct analytics for the Customer's websites and apps
DurationThe term of the Service, plus the deletion period in Section 9
PurposeCollecting, storing and reporting on how people use the Customer's product, including AI-assisted analysis of aggregate results when the Customer uses it
PeopleVisitors and users of the Customer's websites and apps
DataPseudonymous person and session IDs; user IDs and traits the Customer sends; events and their properties; page paths and referrers; browser, device and country; IP address if the Customer enables it; heatmap page captures
Special categoriesNone intended. The Customer must not send special-category data.

13. Annex B: Security measures

  • Every query, export and realtime connection is scoped to one customer project.
  • Role-based access for the Customer's team, with two-factor authentication and passkeys available.
  • ClickClacks staff access requires a separate elevated session with strong authentication, and privileged actions are written to an audit trail.
  • Data is encrypted in transit.
  • IP addresses are not stored unless the Customer enables it; sensitive query parameters are removed in the browser; form fields are left out of page captures.
  • AI features receive aggregate results only, never a person, a session or an individual event.
  • Retention limits are enforced by scheduled deletion.
  • A documented procedure for handling personal data breaches.

Our Security page describes these in more detail.

14. Annex C: Contacts

Privacy and security: dimitri@sigma1.com. Notices to the Customer go to the organization's owners at their account email addresses.