Data Processing Addendum
The terms that apply when Cortality processes personal data on your behalf. This addendum is part of our Terms of Service and applies automatically; no signature is needed. If you need a countersigned copy, email team@cortality.com.
Version 1.0 · Effective October 7, 2026
1. Definitions and roles
This Data Processing Addendum ("DPA") is between Cortality, Inc. ("Cortality") and the customer that agreed to the Terms ("Customer"). Capitalized terms not defined here have the meanings in the Terms.
- Data Protection Laws means all privacy and data protection laws that apply to the processing of Customer Personal Data, including the EU GDPR, the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection, and US state privacy laws such as the California Consumer Privacy Act as amended (the "CCPA").
- Customer Personal Data means personal data within Customer Data that Cortality processes on Customer's behalf in providing the Service.
- "Controller", "processor", "data subject", "personal data", "processing", "personal data breach", "business", "service provider", "sell" and "share" have the meanings given in the Data Protection Laws.
Roles. Customer is the controller (or business) of Customer Personal Data, and Cortality is its processor (or service provider). Where Customer is itself a processor for another controller, Cortality is Customer's subprocessor, and Customer confirms that its controller has authorized this DPA's terms. Cortality is an independent controller only for account, billing and contact data about Customer's users, which our Privacy Policy covers.
2. Processing on Customer's instructions
Cortality processes Customer Personal Data only on Customer's documented instructions, unless the law requires otherwise (in which case Cortality will tell Customer first, unless the law forbids it). Customer's instructions are: the Terms and this DPA; the configuration Customer chooses in the Service and the tag (for example route allowlists, element exclusions, location settings and the optional visitor ID); the aggregate use in section 5 of the Terms, unless Customer opts out; and other written instructions that Customer gives and Cortality accepts. Cortality will tell Customer if it believes an instruction violates Data Protection Laws.
Customer is responsible for the lawfulness of the instructions and of the collection: in particular, for giving visitors the notices and obtaining the consents that Data Protection Laws and wiretap or eavesdropping laws require, as section 6 of the Terms describes. The details of the processing are in Annex I.
3. US state privacy law terms
For Customer Personal Data subject to the CCPA or similar US state laws, Cortality: (a) processes it only for these specific business purposes: collecting, storing and analyzing visitor interactions and masked page renders on Customer's sites to produce the analytics, findings, re-measures and reports Customer requests, and securing and debugging that processing; and, unless Customer opts out under section 5 of the Terms, deidentifying it into aggregate statistics used to build benchmarks and improve Cortality's models, which never identify Customer, its sites or any individual; (b) will not sell or share it; (c) will not retain, use or disclose it outside the direct business relationship with Customer or for any purpose other than those business purposes, except as those laws permit; (d) will not combine it with personal information Cortality receives from other sources, except as those laws permit; (e) will comply with those laws and give the same level of privacy protection they require; and (f) will tell Customer if it can no longer meet these obligations. Cortality will cooperate with Customer in responding to consumer requests that Customer forwards, including by deleting or deidentifying data as 11 CCR §7022 allows, and permits Customer to assess its compliance as provided in section 9. Customer may take reasonable steps to stop and remediate unauthorized use. Cortality certifies that it understands and will comply with these restrictions.
4. Personnel and security
Cortality ensures that people authorized to process Customer Personal Data are bound by confidentiality. Cortality implements and maintains the technical and organizational measures in Annex II, and may update them as long as the overall level of protection does not decrease.
5. Subprocessors
Customer gives Cortality general authorization to engage subprocessors. The current subprocessors are listed in Annex III and on the Subprocessors list. Cortality will post any intended new subprocessor, with its purpose and location, to the dated change log on that list at least 30 days before it receives Customer Personal Data. Customer agrees that this posting is Cortality's written notice of intended changes under Article 28(2) GDPR and Clause 9(a) of the SCCs, and that checking the list is Customer's responsibility. Customer may object within that 30-day period on reasonable data protection grounds by emailing team@cortality.com; the parties will discuss it in good faith, and if Cortality cannot reasonably accommodate the objection, Customer may cancel the affected Service and receive a refund of prepaid fees for the unused period.
Cortality imposes on each subprocessor, by written contract, the same data protection obligations as this DPA, as they apply to the service the subprocessor provides, and remains responsible for its subprocessors' performance.
6. Data subject requests and assistance
Taking into account the nature of the processing, Cortality will help Customer respond to requests from data subjects to exercise their rights. If Cortality receives such a request about Customer Personal Data directly, it will refer the person to Customer and will not respond itself except to confirm that referral. Because the tag does not link visits to an identified person, Customer Personal Data generally cannot be searched by name or email; where a request supplies an identifier the Service holds (such as an optional visitor ID), Cortality will help Customer locate the relevant records.
Cortality will give Customer reasonable information and help with data protection impact assessments and consultations with supervisory authorities, to the extent Customer does not otherwise have that information.
7. Personal data breaches
Cortality will notify Customer without undue delay, and in any case within 72 hours, after becoming aware of a personal data breach affecting Customer Personal Data. The notice will describe, as far as known, the nature of the breach, the categories and approximate volume of data concerned, the likely consequences, and the measures taken or proposed, with updates as facts develop. Cortality will take reasonable steps to contain and remediate the breach. Notice is not an admission of fault.
8. Retention after the Service ends
Cortality's practice is to keep the data it collects, as its Retention policy describes. Unless Customer instructs otherwise under the last point below, Customer instructs Cortality to retain Customer Data, including Customer Personal Data, after the Service ends, on these terms:
- retained data stays encrypted, scoped to Customer's sites, visible only to Customer's account, and protected by this DPA for as long as Cortality holds it;
- it is not accessed or used except on Customer's instructions (such as reports and records Customer asks for), for security, or for legal compliance, and for aggregate use under the Terms unless Customer opted out; it is never sold, shared or used for advertising;
- on Customer's written request at any time, Cortality will provide a copy of Customer Personal Data in a commonly used format;
- if Customer instructs deletion in writing, or Data Protection Laws require it, Cortality will within 30 days, including in archived raw data, either (i) delete Customer Personal Data, or (ii) where Customer has not required deletion, anonymize it so that no individual can be identified by any means reasonably likely to be used: removing session and visitor IDs, location, user-agent strings, full page addresses, query strings and search terms, and removing page renders and page structure that may show personal content. Cortality will confirm completion in writing, commits not to re-identify anonymized data, and binds any recipient to the same. Where the SCCs apply and Customer elects deletion under Clause 8.5, Cortality will delete. Database backups roll off within 7 days. This does not apply where the law requires Cortality to keep the data.
9. Information and audits
Cortality will make available the information reasonably necessary to demonstrate compliance with this DPA, including its published security documentation and written answers to reasonable security questionnaires. If that information is not enough to meet a requirement of Data Protection Laws, Customer may audit Cortality's compliance once in any 12-month period (or after a personal data breach, or when a supervisory authority requires it), with at least 30 days' notice, during business hours, under confidentiality, at Customer's expense, and in a way that does not compromise other customers' data or Cortality's security.
10. International transfers
Cortality processes Customer Personal Data in the United States. To the extent a transfer from the EEA, the UK or Switzerland to Cortality requires a transfer mechanism, the parties enter into the Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914 ("SCCs"), which are incorporated by reference: Module Two (controller to processor) where Customer is a controller, and Module Three (processor to processor) where Customer is a processor. For the SCCs: clause 7 (docking) applies; in clause 9, option 2 (general authorization) applies with the 30-day advance notice period in section 5 of this DPA; the optional language in clause 11 does not apply; clauses 17 and 18 are governed by and resolved in the courts of Ireland; and Annexes I to III of this DPA complete the SCCs' annexes. For UK transfers, the UK International Data Transfer Addendum to the SCCs (version B1.0) applies, with Table 4's choice left to either party. For Swiss transfers, the SCCs apply with references to the GDPR read as references to the Swiss FADP, and the Swiss FDPIC as the competent authority; the term "member state" does not exclude data subjects in Switzerland from suing in their place of habitual residence. If the SCCs conflict with this DPA, the SCCs prevail.
11. General
This DPA lasts as long as Cortality processes Customer Personal Data. Each party's liability under this DPA is subject to the limitations in the Terms, except where Data Protection Laws or the SCCs do not allow it. If this DPA conflicts with the Terms, this DPA prevails for the processing of Customer Personal Data. This DPA is governed by the same law as the Terms, except where the SCCs require otherwise. Cortality may update this DPA to reflect changes in Data Protection Laws or the Service; it will not reduce the protection given to Customer Personal Data without Customer's agreement.
Annex I. Details of processing
| Item | Details |
|---|---|
| Data exporter | Customer, as identified in its account. Contact: the account owner's email. Role: controller (or processor). Activities: use of the Service to measure its websites. |
| Data importer | Cortality, Inc., 6650 SW 57th Ave, South Miami, FL 33143, USA. Contact: team@cortality.com. Role: processor (or subprocessor). |
| Data subjects | Visitors to the web pages where Customer installs the Cortality tag. |
| Categories of personal data | Interaction events (pointer movement, scrolls, clicks, taps) with coordinates and times; renders of the page as displayed, with form field values masked in the browser; sanitized page structure; device type, viewport size and user-agent string; page path, campaign (UTM) tags and referrer hostname; addresses of links to other sites, with query strings (up to 512 characters); on Shopify checkout pages, the full page address including query strings, and on-site search terms; approximate location (country, region, city; country only for the EEA, UK and Switzerland), derived from the connection and not stored with the IP address; a random per-visit session ID; and, only if Customer turns it on, a random visitor ID stored in the visitor's browser. Cortality does not intend to collect names, contact details, form values or keystrokes, but page renders can show personal content that the page displays outside form fields unless Customer excludes it (Terms section 6). If Customer turns on the optional gaze module and a visitor grants camera access, derived gaze points (never camera images). |
| Sensitive data | None intended. Customer must not install the tag on pages with sensitive data (Terms section 6). |
| Frequency | Continuous, while the tag is installed. |
| Nature and purpose | Collection, storage, analysis (including automated and machine-learning analysis of page renders and aggregate metrics), and presentation of findings, reports and re-measures to Customer. |
| Retention | As section 8 of this DPA and the Retention policy describe. |
| Subprocessor processing | As listed in Annex III, for the purposes stated there, for the duration of the Service and any retention. |
| Supervisory authority | Where Customer is established in the EEA, the authority of that member state; otherwise, as clause 13 of the SCCs determines. |
Annex II. Security measures
- Encryption: TLS for every connection (tag to ingest, content delivery, dashboard); data at rest in Amazon S3 and Amazon RDS encrypted with AWS KMS keys.
- Data minimization at the source: form field values are masked in the visitor's browser before transmission, both in the page structure and in screenshots; no keystrokes and no cookies; random per-visit IDs; IP addresses are not stored with analytics data and are removed before logs are written.
- Network and architecture: ingestion separated from the dashboard and from processing; processing in isolated functions inside a private network (VPC); the database has no public endpoint.
- Access control: single sign-on with scoped roles for staff access to AWS; least-privilege roles per service; dashboard sessions re-validated on every request so revocation is immediate; passwords stored as bcrypt hashes (cost 12) and checked against known breaches.
- Submission integrity: every data submission is signed (HMAC-SHA256) and verified before it is accepted, with short-lived signing keys bound to the site's registered origin, and per-site rate limits.
- Tenant isolation: every record is keyed by site, and queries and file access are scoped server-side to the authenticated customer's sites.
- Logging and monitoring: account-level audit logging (AWS CloudTrail, with file validation); service logs kept 30 days; automated alarms on processing failures.
- Resilience: automated database backups with 7-day point-in-time recovery; versioned storage for collected data.
- Incident response: a documented process to contain, assess, notify within 72 hours, and remediate (see the Trust Center).
- Subprocessors: image analysis providers receive only masked page renders, never event streams, session IDs or form values; Customer can restrict visual analysis to a single provider.
Annex III. Subprocessors
| Subprocessor | Purpose | Location |
|---|---|---|
| Amazon Web Services, Inc. | Hosting, storage, processing, content delivery | USA (us-east-1); delivery network edge locations in transit only |
| Alibaba Cloud (Model Studio / DashScope) | Visual analysis of masked page renders (default image model) | US-region endpoint |
| xAI Corp. (Grok API) | Writing the weekly findings note from masked page renders, the page's text and aggregate counts | US-region endpoint |
| Anthropic, PBC (Claude API) | Investigating aggregate metrics and the page's published content to write findings; no images, no event streams | USA (not region-pinned) |
| Google LLC (Gemini API) | Alternate visual-analysis provider, used only when selected | Global endpoint (not region-pinned) |
| Resend, Inc. | Delivering emails to Customer's users, including report and findings content | USA |
