Data processing agreement
Version of 1 October 2026 · Article 28 of the General Data Protection Regulation (GDPR)
This agreement is part of the Terms of Service between the Customer and HSLP, which operates Freqo. It applies automatically to every Freqo account; no signature is needed. If you need a signed copy for your records, write to hello@freqo.eu.
1. Roles
For the statistics collected on the Customer's websites, the Customer is the controller and HSLP is the processor. HSLP processes this data only on the Customer's documented instructions, which are these terms, the settings chosen in the dashboard, and any written instruction sent by the Customer. HSLP will tell the Customer if it believes an instruction infringes data protection law.
2. Description of the processing
| Purpose | Measuring the audience of the Customer's websites and producing statistics for the Customer. |
|---|---|
| Nature | Collection through a script on the Customer's websites, storage, aggregation and display in the dashboard, export at the Customer's request, deletion. |
| Duration | For as long as the Customer's account exists. Statistics are deleted automatically after 25 months. |
| Data subjects | Visitors of the Customer's websites. |
| Data, for every visitor | Address of the page viewed, referring page and campaign tags, date and time, country (derived from the IP address, which is not stored), type of device, browser and operating system (derived from the user agent, which is not stored), screen width, browser language, time spent, scroll depth, page performance measures, interactions measured by the Customer (downloads, outbound links, actions matching the Customer's goals, custom events), a random visit identifier, and a daily pseudonymous count key computed from the IP address and browser with a secret that is deleted every day. |
| Additional data, only with consent | A random visitor identifier stored in the visitor's browser for 13 months at most, used to recognise return visits to the same website, and the record of the visitor's choice. |
| Special categories | None. The Customer must not send special categories of data, nor names, email addresses or other direct identifiers, through page addresses, events or event properties. |
3. HSLP's obligations
- Confidentiality: only people who need it to run the Service can access the data, and they are bound by confidentiality.
- Security: HSLP applies the technical and organisational measures listed in the annex and keeps them up to date.
- Sub-processors: see section 4.
- Assistance: HSLP helps the Customer, as far as possible, to answer requests from data subjects, to carry out data protection impact assessments and to consult the supervisory authority where needed.
- Personal data breaches: HSLP notifies the Customer without undue delay, and at the latest 48 hours after becoming aware of a breach affecting the Customer's data, with the information available to help the Customer meet its own obligations.
- Deletion: when the Customer deletes a website or its account, the related data is deleted from live systems immediately and from backups within 14 days. HSLP keeps no copy, unless the law requires it.
- Audits: HSLP makes available the information needed to show compliance with this agreement. The Customer may carry out an audit, at its own cost, once a year with 30 days' notice, by itself or through an independent auditor bound by confidentiality, in a way that does not disrupt the Service or the security of other customers' data.
- Location: visitor statistics are stored and processed in Switzerland, a country recognised by the European Commission as offering an adequate level of protection. They are not transferred elsewhere.
4. Sub-processors
The Customer gives HSLP a general authorisation to use sub-processors. The current sub-processor for visitor statistics is:
| Sub-processor | Service | Location of the data |
|---|---|---|
| OVH SAS (OVHcloud), 2 rue Kellermann, 59100 Roubaix, France | Server hosting | Zurich, Switzerland |
HSLP will announce any new sub-processor on this page and by email at least 30 days in advance. The Customer may object for legitimate reasons; if no solution is found, the Customer may terminate the affected subscription. HSLP imposes the same data protection obligations on its sub-processors and remains responsible for them.
5. The Customer's obligations
- Have a lawful basis for the audience measurement of its websites and inform visitors in its privacy policy.
- Choose the tracking mode that fits its obligations, and collect consent where it is required (the Freqo banner or the Customer's own consent tool can be used for this).
- Configure the Service so that no unnecessary personal data is sent to it.
Annex: technical and organisational measures
- Encryption of all connections with HTTPS (TLS).
- Visitor IP addresses are used only at the time of collection, to derive the country and the daily count key, and are never stored, including in server logs.
- The secret used for the daily count key changes every day and the previous one is deleted, so anonymous visitors cannot be recognised across days.
- Databases run on a private network and are not reachable from the internet. Each service runs in an isolated container.
- Server administration only by our team, with personal credentials. Dashboard passwords are hashed with scrypt; sessions are stored as hashes and expire after 30 days.
- Protection against abuse: rate limits on logins, sign-ups and data collection, checks that data comes from the declared websites, and filtering of bots.
- Strict security headers and protection against cross-site requests on the dashboard.
- Automatic deletion of statistics after 25 months; daily backups kept for 14 days.
- Every customer's data is separated: each request checks that the user has access to the website concerned.