1. Roles
For visitor and form-submitter data on websites you build with SinceCode, you are the Controller and SinceCode is the Processor. For your SinceCode account data, SinceCode is the Controller (see the Privacy Policy).
2. Subject matter
- Subject matter: hosting the Customer's site, serving its pages, capturing form submissions, producing analytics.
- Duration: for the lifetime of the Customer's SinceCode account plus retention.
- Data subjects: the Customer's visitors and form submitters.
- Personal data: analytics — country code, URL, referrer domain, device family, timestamp (no IP, no UA, no visitor id stored). Form submissions — whatever the Customer collects.
3. Customer instructions
SinceCode processes personal data only on the Customer's documented instructions: the Terms, this DPA, and the Customer's use of the Service.
4. Confidentiality
Personnel authorised to process the data are bound by confidentiality.
5. Security (Art. 32)
- Encryption in transit (HTTPS/TLS).
- Encryption at rest for the application database.
- bcrypt password hashing; optional TOTP 2FA.
- Role-based access control with audit logging.
- Routine patching, daily encrypted backups, periodic restore testing.
- Rate limiting, bot challenge, DDoS protection.
6. Sub-processors
The Customer authorises SinceCode to use the sub-processors listed at /sub-processors. We notify the Customer before adding or replacing a sub-processor.
7. Assistance
SinceCode assists the Customer with data-subject rights, security, breach notification and DPIAs.
8. Breach notification
Notify the Customer without undue delay and within 72 hours of becoming aware of a personal-data breach affecting the Customer's data.
9. End of services
On termination, the Customer can export the data via the in-product tool, or accept anonymisation followed by deletion after 30 days, as described in the Privacy Policy.
10. Audit rights
Information requests via privacy@sincecode.com. On-site audits agreed in advance, scoped to genuine need, under confidentiality.
11. International transfers
UK adequacy decisions and standard contractual clauses in sub-processor contracts, per Article 46.
12. Acceptance
The Customer accepts this DPA on first use of SinceCode for processing third-party personal data.