Data Processing Addendum (Core)

Effective date: 2026-08-11 · Version 1.0

1. About this addendum

This Data Processing Addendum ("Core DPA") supplements the Terms of Service between you ("Customer", "Controller") and Backstory Pty Ltd ("Backstory", "Processor") for the Core Backstory Analytics product (company-level website identification and journey attribution). It applies automatically, by click-through acceptance at signup or first use, to the extent Backstory processes personal data on Customer's behalf as a processor while providing the Service. It does not cover the optional Contacts add-on, which has its own Leads DPA.

We offer this Core DPA even though our processing is minimized by design (no cookies, no raw IP at rest, 8-hour session TTL) — see our Legitimate Interest Assessment — because the session hash we compute is pseudonymous personal data under GDPR Article 4(5), and every comparable company-level analytics vendor on the market offers a DPA rather than a "no personal data" claim.

2. Subject matter, duration, nature and purpose

Subject matter: Backstory's processing of personal data collected via the tracking script and dashboard, on Customer's instructions, to provide website account-identification analytics.

Duration: for the term of the underlying Terms of Service, plus any post-termination retention described in our Privacy Policy.

Nature and purpose: server-side session correlation, company/ASN enrichment, and journey attribution as described in our Privacy Policy Part A; dashboard hosting and support.

Categories of data subjects: Customer's website visitors (pseudonymously, via session hash); Customer's own personnel who access the dashboard.

Categories of personal data: truncated-IP-derived session hash, coarse geography/company data, page paths, referrer, UTM parameters, device/browser category; for dashboard users, account email and usage data.

3. Processor obligations

Backstory will:

  1. Process personal data only on Customer's documented instructions (including this DPA and the Terms), unless required otherwise by law, in which case Backstory will inform Customer unless prohibited from doing so.
  2. Ensure personnel authorized to process personal data are subject to confidentiality obligations.
  3. Implement appropriate technical and organizational measures (Section 6) against unauthorized or unlawful processing and against accidental loss, destruction, or damage.
  4. Only engage sub-processors listed on our Sub-processor list page, itself sourced from our Article 30 processor register. We will give reasonable notice before adding a new sub-processor that materially changes processing, and Customer may object on reasonable data-protection grounds by contacting legal@trybackstory.com.
  5. Assist Customer, taking into account the nature of the processing, in responding to data-subject requests and in meeting Customer's own Article 32–36 GDPR obligations (security, breach notification, DPIAs), to the extent applicable.
  6. Notify Customer without undue delay after becoming aware of a personal data breach affecting Customer's data.
  7. At the end of the Service relationship, delete or return personal data per Customer's choice, subject to the retention periods described in our Privacy Policy for legal-compliance purposes.
  8. Make available information reasonably necessary to demonstrate compliance with this DPA, and allow for audits by Customer or an appointed auditor on reasonable notice, subject to confidentiality.

4. Controller obligations

Customer confirms it has a lawful basis for the instructions it gives Backstory, and that its use of the Service (including implementation of the tracking script) complies with applicable data-protection law, including providing its own website visitors with an adequate privacy notice. See our Acceptable Use Policy.

5. International transfers

Where personal data is transferred outside the EEA or UK to a sub-processor without an adequacy decision, Backstory relies on the European Commission's Standard Contractual Clauses (Module 3: Processor to Sub-processor / Module 2 as applicable) and, for transfers subject to UK GDPR, the UK International Data Transfer Addendum (IDTA), each incorporated by reference and available on request from legal@trybackstory.com.

6. Technical and organizational measures (summary)

  • Encryption in transit (TLS) for all data in motion; encryption at rest for stored data.
  • Access controls and least-privilege service credentials; role-based access to the dashboard.
  • Data minimization by design: no raw IP at rest, no cookies on the tracking script, 8-hour session TTL, daily salt rotation.
  • Logging with IP redaction (personal data is not written to application logs or error-tracking in identifiable form).
  • Vendor/sub-processor due diligence per our Article 30 processor register.

7. Liability and term

Liability under this DPA is governed by the limitation-of-liability provisions of the Terms of Service. This DPA remains in effect for as long as Backstory processes personal data on Customer's behalf under the Terms.

8. Governing law

This DPA is governed by the laws of Australia, except that the SCCs/IDTA referenced in Section 5 are governed by their own terms as required by EU/UK law.

9. Contact Us

Questions about this DPA: legal@trybackstory.com.