Roles
You are the data controller for the websites and implementations you operate. Glytiq acts as the data processor when processing visitor statistics on your documented instructions and only to provide, secure and support the analytics service.
Scope and duration
Processing covers pageview statistics, configured events, goals, funnels, revenue measurements, AI referral measurements and related account settings for the duration of your subscription. Upon termination, customer analytics data is deleted from active systems and then from backups according to the documented retention cycle.
Sub-processors and hosting
Glytiq uses Railway for application hosting in EU West (Amsterdam) and TiDB Cloud on AWS for its production database in Frankfurt. Separate providers handle transactional email and payment processing for billing data. Visitor analytics data is not sent to the payment processor. A current region and provider statement is available on request before contract signature.
Security measures
Safeguards include encryption in transit, encryption at rest where supported by the managed infrastructure, hashed credentials and API keys, least-privilege application access, administrative audit logging, transient handling of visitor IP addresses, and optional tracker controls for consent or opt-out workflows.
Data subject requests
Glytiq's core analytics records are designed around non-identifying measurements, but account data and customer-supplied custom properties may fall within data-protection law. We will provide reasonable assistance for requests that concern data we process on your behalf.
Incident notification
If we become aware of a security incident affecting customer data, we will notify the affected customer without undue delay, share the information reasonably available about the nature and impact of the incident, and describe the mitigation steps being taken.