Effective date: 2026-08-11 · Version 1.0
This Data Processing Addendum ("Core DPA") supplements the Terms of Service between you ("Customer", "Controller") and Backstory Pty Ltd ("Backstory", "Processor") for the Core Backstory Analytics product (company-level website identification and journey attribution). It applies automatically, by click-through acceptance at signup or first use, to the extent Backstory processes personal data on Customer's behalf as a processor while providing the Service. It does not cover the optional Contacts add-on, which has its own Leads DPA.
We offer this Core DPA even though our processing is minimized by design (no cookies, no raw IP at rest, 8-hour session TTL) — see our Legitimate Interest Assessment — because the session hash we compute is pseudonymous personal data under GDPR Article 4(5), and every comparable company-level analytics vendor on the market offers a DPA rather than a "no personal data" claim.
Subject matter: Backstory's processing of personal data collected via the tracking script and dashboard, on Customer's instructions, to provide website account-identification analytics.
Duration: for the term of the underlying Terms of Service, plus any post-termination retention described in our Privacy Policy.
Nature and purpose: server-side session correlation, company/ASN enrichment, and journey attribution as described in our Privacy Policy Part A; dashboard hosting and support.
Categories of data subjects: Customer's website visitors (pseudonymously, via session hash); Customer's own personnel who access the dashboard.
Categories of personal data: truncated-IP-derived session hash, coarse geography/company data, page paths, referrer, UTM parameters, device/browser category; for dashboard users, account email and usage data.
Backstory will:
Customer confirms it has a lawful basis for the instructions it gives Backstory, and that its use of the Service (including implementation of the tracking script) complies with applicable data-protection law, including providing its own website visitors with an adequate privacy notice. See our Acceptable Use Policy.
Where personal data is transferred outside the EEA or UK to a sub-processor without an adequacy decision, Backstory relies on the European Commission's Standard Contractual Clauses (Module 3: Processor to Sub-processor / Module 2 as applicable) and, for transfers subject to UK GDPR, the UK International Data Transfer Addendum (IDTA), each incorporated by reference and available on request from legal@trybackstory.com.
Liability under this DPA is governed by the limitation-of-liability provisions of the Terms of Service. This DPA remains in effect for as long as Backstory processes personal data on Customer's behalf under the Terms.
This DPA is governed by the laws of Australia, except that the SCCs/IDTA referenced in Section 5 are governed by their own terms as required by EU/UK law.
Questions about this DPA: legal@trybackstory.com.