Skip to content
Privacy and law

What is Data processing agreement (DPA)?

A data processing agreement is the contract the GDPR requires whenever one organisation processes personal data on another's behalf. If your analytics vendor handles personal data for you, you are the controller, they are the processor, and Article 28 requires this contract to exist before the processing starts.

Explanatory, not legal advice.

Controller and processor

The controller decides why and how personal data is processed — that is you, the site owner. The processor acts on the controller’s instructions — that is the vendor.

The distinction assigns responsibility. The controller answers to regulators and to data subjects for the whole arrangement, including its choice of processor. “The vendor handled it” is not a defence.

What Article 28 requires it to contain

  • Subject matter, duration, nature and purpose of the processing.
  • Categories of personal data and of data subjects.
  • Processing only on documented instructions from the controller.
  • Confidentiality obligations on anyone with access.
  • Appropriate security measures.
  • Terms for engaging sub-processors, including notice of changes.
  • Assistance with data-subject requests and breach notification.
  • Deletion or return of the data when the service ends.
  • Audit and inspection rights.

Sub-processors are the part people miss

Vendors use vendors. Your analytics provider’s hosting, database and email services may each touch data, and each needs to be covered. A vendor should publish its sub-processor list and give notice before changing it — if it will not, you cannot honestly complete your own records of processing.

When you may not need one at all

A DPA is required because personal data is being processed. Where a vendor processes none on your behalf, the Article 28 trigger does not arise.

That is worth verifying rather than assuming from a marketing page, because “anonymous” is used loosely. Ask the specific question: is any identifier retained that could single out a visitor across visits? If the answer is no, and it holds up, the contract requirement has nothing to attach to. If you need a signed DPA for your own records regardless, ask for one — a serious vendor will provide it either way.

Questions

Frequently asked.

Cookies, install and pricing, answered. Still stuck? Ask us anything .

01 Can sonex show revenue next to my traffic?

Yes. Connect Stripe or Polar with a read-only key and sonex reads revenue straight from your payment provider, per website. Revenue then appears as a focusable series on the Overview chart and as its own report, beside the traffic that earned it. No tracked event is needed for it to work.

02 Does sonex use cookies?

No. sonex sets no cookies and needs no consent banner. It counts visits without cookies, fingerprinting, or any personal data, so it is GDPR, PECR and CCPA-ready by default.

03 How do I install sonex?

Add one script tag to your site's <head> with your website id. It is a single lightweight tracker — no build step and no SDK required.

04 Is sonex a Google Analytics alternative?

Yes. sonex gives you the reports that matter — visitors, pages, referrers, funnels, revenue and a world map — without surveilling your audience or drowning you in configuration.

05 How is sonex priced?

By monthly tracked events. Free covers 2k events, Pro is $20/mo for 200k events, and Business is $200/mo for 2M events with team seats.

See what your traffic actually earns.

Revenue beside the visitors that produced it. No cookies, no credit card, no consent banner.

Get started