Data processing agreement
Version 1.0 - August 31, 2026
On this page
1. Parties and applicability
This Data Processing Agreement forms part of the agreement between:
Metrara, part of Goldcompass, based in Dordrecht, the Netherlands, Chamber of Commerce 87161079, hereinafter "Processor";
and
the customer taking out an account or subscription with Metrara, hereinafter "Controller".
1.1 This agreement applies automatically as soon as the customer creates an account or takes out a subscription, and remains in force for as long as Processor processes personal data on behalf of Controller.
1.2 This agreement meets the requirements of Article 28 GDPR.
1.3 In the event of a conflict between this agreement and Metrara's terms and conditions, this agreement prevails where the processing of personal data is concerned.
2. What Processor does and does not do
2.1 Processor processes personal data solely on documented instructions from Controller. Use of the service, including the connections Controller activates and the settings Controller chooses, constitutes such an instruction.
2.2 Processor does not process personal data for its own purposes, does not sell it, and does not use it to train AI models.
2.3 All connections to external platforms are read-only. Processor never changes anything in Controller's connected accounts.
2.4 If Processor considers an instruction to be in breach of the GDPR or other legislation, it will notify Controller without delay.
3. Nature and purpose of the processing
3.1 Processor provides an online marketing dashboard that retrieves, combines, analyses and presents data from connected sources.
3.2 A detailed description of the processing is set out in Annex 1.
3.3 The processing concerns aggregated marketing data in principle. Personal data of Controller's own end customers is not processed deliberately, but may appear incidentally in the source data retrieved.
4. Controller's obligations
4.1 Controller is responsible for the lawfulness of the processing, including the legal basis, the duty to inform data subjects, and obtaining any consent required.
4.2 Controller warrants that it is authorised to connect the accounts it connects, and that it has the permission of the rights holder to do so.
4.3 Where Controller is an agency connecting accounts belonging to its own clients, Controller ensures that it is entitled to do so and that it has made the necessary arrangements with those clients. In that case Processor acts as sub-processor.
5. Security
5.1 Processor implements appropriate technical and organisational measures as referred to in Article 32 GDPR. An overview is set out in Annex 2.
5.2 Processor ensures that persons with access to personal data are bound by confidentiality.
5.3 Processor limits access to personal data to what is necessary for providing and maintaining the service.
5.4 Processor may adjust these measures, provided the level of protection is not reduced.
6. Sub-processors
6.1 Controller gives general authorisation for the engagement of sub-processors. The current list is set out in Annex 3 and on metrara.com.
6.2 Processor enters into an agreement with each sub-processor containing data protection obligations no less strict than those in this agreement.
6.3 When adding or replacing a sub-processor, Processor informs Controller at least thirty days in advance by email or within the service.
6.4 Controller may object on reasoned grounds within fourteen days of that notice. If the parties cannot reach agreement, Controller may terminate the agreement as of the date the change takes effect, without charge and with a refund of amounts prepaid for the remaining period.
6.5 Processor remains fully liable for the performance of its sub-processors.
7. Transfers outside the EU
7.1 Personal data is stored within the European Union.
7.2 For certain features, Processor engages sub-processors established outside the EU. These are listed with their location in Annex 3.
7.3 Transfers to these parties take place on the basis of an adequacy decision of the European Commission, or on the basis of the Standard Contractual Clauses, supplemented with appropriate additional measures.
7.4 No personal data of Controller's own end customers is sent to sub-processors outside the EU.
8. Requests from public authorities
8.1 Any request from a public authority for personal data processed under this
agreement is assessed by the management of Processor for its legal basis and its
scope before any data is disclosed. Where the basis is unclear, Processor obtains
legal advice.
8.2 Processor challenges or refuses a request that it considers unlawful, or that
goes beyond what the law requires, and informs Controller of the request unless
it is prohibited by law from doing so.
8.3 Processor discloses only the minimum personal data strictly required by the
request. Requests for bulk or unspecified data are refused.
8.4 Processor documents every request: the requesting authority, the legal basis
invoked, what was disclosed and why, and who decided. This documentation is
available to Controller on request, insofar as the law permits.
9. Data subject rights
9.1 If Processor receives a request from a data subject, it will refer that person to Controller and inform Controller within five working days.
9.2 Processor provides reasonable assistance in handling requests for access, rectification, erasure, restriction, objection and portability.
9.3 Controller can view, export and delete most data itself through the service. Processor charges nothing for assistance that is possible through the service's standard functions.
10. Personal data breaches
10.1 Processor informs Controller without undue delay, and no later than forty-eight hours after discovery, of a personal data breach.
10.2 The notification includes at least the nature of the breach, the categories and approximate numbers concerned, the likely consequences, and the measures taken or proposed.
10.3 Processor provides reasonable assistance with notification to the supervisory authority and data subjects. The notification itself is Controller's responsibility.
10.4 Processor maintains a register of breaches.
11. Assistance and data protection impact assessment
11.1 Processor provides reasonable assistance with a data protection impact assessment or a prior consultation of the supervisory authority, insofar as it relates to the service.
11.2 For assistance requiring substantially more time than answering questions, Processor charges a rate of € 125 per hour (excluding VAT). Processor provides an estimate of the expected time in advance.
12. Audits
12.1 On request, Processor makes available the information necessary to demonstrate compliance with the obligations in this agreement, including a description of its security measures, documentation of its sub-processors, and the certifications and audit reports those sub-processors have provided.
12.2 If the information provided under 11.1 does not reasonably demonstrate Processor's compliance with this agreement, Controller may have an audit carried out no more than once a year by an independent auditor bound by confidentiality. Controller gives at least thirty days' written notice, stating the scope and the reason.
12.3 The parties agree the timing, scope and method of the audit by mutual arrangement. The audit does not unnecessarily disrupt Processor's operations, remains limited to what is necessary for the stated purpose, and gives no access to other customers' data or to Processor's source code.
12.4 The costs of the audit are borne by Controller. This includes the auditor's fees and compensation for the time Processor spends on the audit, at a rate of € 125 per hour (excluding VAT). Processor provides an estimate of the expected time in advance. If the audit reveals a material failure on the part of Processor, these costs are borne by Processor.
12.5 An additional audit is permitted following a personal data breach at Processor affecting Controller, or at the request of a competent supervisory authority.
13. Retention and deletion
13.1 After termination of the agreement, Processor retains the data for ninety days, so that Controller can export it or reactivate its account.
13.2 After those ninety days, Processor deletes all personal data automatically and irreversibly, including at its sub-processors, unless legislation requires longer retention.
13.3 Controller may request earlier deletion during that period.
13.4 On request, Processor confirms the deletion in writing.
14. Liability
14.1 The liability provisions in Metrara's terms and conditions apply, subject to mandatory law.
14.2 Article 82 GDPR remains fully applicable.
15. Term and amendments
15.1 This agreement runs for as long as Processor processes personal data on behalf of Controller, and ends after expiry of the retention period in Article 12.
15.2 Processor may amend this agreement where legislation, case law or the service gives cause to do so. Amendments are announced at least thirty days in advance.
15.3 Obligations which by their nature continue, including confidentiality, remain in force after termination.
16. Governing law
16.1 This agreement is governed by Dutch law.
16.2 Disputes will be submitted to the competent court in the district of Rotterdam.
Annex 1 — Description of the processing
Subject matter: the provision of an online marketing dashboard.
Duration: the term of the subscription, plus ninety days.
Nature of the processing: retrieving, storing, combining, analysing, presenting and, on request, deleting data from connected sources.
Purpose: providing insight into marketing performance and generating improvement suggestions, tasks and reports.
Categories of data subjects:
- Controller's users, including read-only accounts
- Visitors and customers of Controller's websites, insofar as their data appears in the source data retrieved
- Recipients of Controller's email campaigns, at aggregated level
Categories of personal data:
- User account details: name, email address, encrypted password, role
- Website traffic statistics, keywords and rankings
- Advertising performance and search terms
- Order and revenue data, in principle at product and category level
- Reach and engagement on social channels
- Email campaign statistics
Special categories of personal data: not processed.
Annex 2 — Security measures
Access
- Role-based access, with the minimum rights necessary
- Separation of data per organisation at database level
- Logging of access to systems and data
- Two-factor authentication on infrastructure accounts
Encryption
- Encrypted connections (TLS) for all data traffic
- Encrypted storage of passwords and access tokens
- Encryption of data at rest at the hosting provider
Connections
- Read-only permissions on external platforms
- Tokens are stored encrypted and separated per organisation
- Controller can revoke connections at any time
Continuity
- Regular database backups
- Recovery procedure in the event of data loss or corruption
Organisational
- Confidentiality obligation for everyone with access to data
- Register of personal data breaches
- Periodic review of sub-processors
Annex 3 — Sub-processors
- TransIP - Hosting of metrara.com - Netherlands
- Vercel - Hosting of the dashboard application - EU (Dublin), US parent company
- Supabase - Database, file storage and authentication - EU (Ireland), US parent company
- Mollie - Billing and collection - Netherlands
- Resend - Transactional and service email - United States
- Anthropic (Claude) - Generating texts, summaries and advice - United States
For search volumes, rankings, competitor data and backlink data, Processor uses specialised data providers. Only keywords, domain names and URLs are sent to these parties, never personal data. They are therefore not sub-processors. Names are shared on request.
This is a translation. In the event of any discrepancy, the Dutch version prevails.
