Coruve

Legal

Data Processing Agreement

UK GDPR Article 28 terms for customers who process their users' data through Coruve — incorporated into the Terms automatically.

Last updated · 11 August 2026

Clause 1. Parties, scope and incorporation

This Data Processing Agreement ("DPA") forms part of the Coruve Terms of Service and applies whenever a customer (the "Customer", acting as controller) uses Coruve (the "Processor") to process personal data of the Customer's website or product users ("Customer Personal Data"). It is entered into by acceptance of the Terms — no signature is required, and it is effective for as long as Coruve processes Customer Personal Data.

Terms like "controller", "processor", "personal data", "processing" and "data subject" have the meanings given in the UK GDPR.

Company details: the registered legal entity name, company number, and registered office address for Coruve will be published here upon incorporation. If your organisation requires a countersigned copy of this DPA, contact [email protected].

Clause 2. Details of the processing

Description
Subject matterAnalytics on the Customer's websites and applications via the Coruve snippet and APIs.
DurationThe term of the Customer's agreement, plus the deletion periods described in section 6.
Nature and purposeCollection, pseudonymisation, storage, aggregation, and reporting of usage events so the Customer can understand product and website behaviour.
Data subjectsVisitors and users of the Customer's websites and applications.
Categories of dataPseudonymised visitor identifiers (daily-rotating salted hashes); usage events and pages viewed; referrer and campaign parameters; technical data (browser and OS family, viewport); coarse location (country, region, city — derived from the visitor's network, never precise coordinates, and configurable to a coarser level per project). IP addresses are processed transiently to derive that location and are not stored.
Special categoriesNone. The Service is not designed for them and the Customer agrees not to submit them (Terms, section 5).

Clause 3. Coruve's obligations as processor

Coruve will:

  • Process Customer Personal Data only on the Customer's documented instructions — which are: to provide the Service as configured by the Customer — unless required to do otherwise by law, in which case we will inform the Customer unless the law prevents it.
  • Ensure everyone authorised to process Customer Personal Data is bound by confidentiality obligations.
  • Implement appropriate technical and organisational measures (UK GDPR Article 32), including: encryption in transit, double salted hashing of visitor identifiers, transient-only IP handling, least-privilege access tokens, separated production and staging environments, and automatic storage-layer deletion at the end of the retention period.
  • Assist the Customer, taking into account the nature of the processing, in responding to data subject rights requests and in meeting the Customer's obligations under UK GDPR Articles 32–36 (security, breach notification, DPIAs).
  • Notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, with enough information to meet the Customer's own notification duties.
  • Delete Customer Personal Data at the end of the provision of the Service (and automatically at the end of each event's retention period), unless UK law requires storage. Aggregated data that identifies no individual may be retained.
  • Make available the information reasonably necessary to demonstrate compliance with this DPA, and allow for and contribute to audits as described in section 7.

Clause 4. Sub-processors

The Customer gives general written authorisation for Coruve to use the following sub-processors — the providers that process Customer Personal Data, drawn from the full provider list published in our Privacy Policy:

Sub-processorPurposeLocation
RailwayCloud hosting, application servers, and the application databaseNetherlands (Amsterdam)
HostingerCloud infrastructure for our self-hosted analytics event store (ClickHouse, operated by Coruve)Germany (Frankfurt)
AnthropicAI event labeling — receives event names and draft labels only, never visitor-level dataUnited States
CloudflareBot protection on authentication surfacesGlobal

We will update this list and give customers notice (by email or the changelog) at least 14 days before adding or replacing a sub-processor. If the Customer reasonably objects on data protection grounds and we cannot offer an alternative, the Customer may terminate the affected service and receive a pro-rata refund of prepaid fees.

Coruve imposes data protection obligations on each sub-processor equivalent to those in this DPA and remains liable for their performance.

Clause 5. International transfers

Where processing involves a transfer of Customer Personal Data outside the UK, Coruve ensures a valid transfer mechanism under UK GDPR: UK adequacy regulations (including the UK–US Data Bridge where the recipient is certified), or the ICO's International Data Transfer Agreement / UK Addendum, together with supplementary measures where appropriate. Note that the analytics event store itself is a ClickHouse database operated by Coruve on dedicated infrastructure in Germany (Hostinger, Frankfurt).

Clause 6. Deletion and return of data

  • Continuous deletion: every event is stamped with the plan's retention period at ingestion (30 days to 3 years, by plan) and deleted automatically at the storage layer when it expires.
  • Self-service return: the Customer can export data at any time via the CSV export available on every report.
  • On termination: Customer Personal Data is deleted following account closure in line with the retention rules, except where retention is required by law.

Clause 7. Audits

On written request (no more than once in any 12-month period, on at least 30 days' notice), Coruve will make available the information reasonably necessary to demonstrate compliance with this DPA, and will permit an audit — conducted so as not to disrupt the Service, at the Customer's cost, and subject to confidentiality. Where a recognised third-party audit report or certification covering the relevant controls exists, it may be provided in satisfaction of the request.

Clause 8. Liability and precedence

Each party's liability under this DPA is subject to the limitations and exclusions in the Terms of Service, except where UK GDPR does not permit such limitation. If this DPA conflicts with the Terms on a data protection matter, this DPA prevails.

Questions about this DPA: [email protected].

Data Processing Agreement | Coruve