LogClip

Legal

Data Processing Agreement

The terms under which LogClip processes personal data on your behalf, as required by Article 28 of the GDPR. It forms part of your agreement with us and applies whenever the data you send us includes personal data.

DraftVersion 1.0 · Published for review 27 August 2026

This agreement is published so you can review it before you need it. It is not yet offered for signature: the breach-notification and data-subject-request procedures it describes are being put in place. Ask us for the current signable version.

Read this alongside the product, not instead of it

Every control described in Annex II is one you can verify in the product or in our security documentation. Where something is not yet true, this document says so rather than leaving it out.

1. Scope and roles

You are the controller. You decide what to record, on which sites, with what masking, and for how long. You determine the purposes and means of the processing.

Siddi Tek LLC is the processor. We process personal data only to provide the service to you. This agreement applies to all such processing and prevails over any conflicting term in the main agreement in respect of data protection.

“Personal data”, “controller”, “processor”, “processing”, “data subject” and “personal data breach” have the meanings given in the GDPR. “Data Protection Law” means Regulation (EU) 2016/679 and any other data protection law that applies to the processing.

2. Instructions

We process personal data only on your documented instructions, including on transfers, unless required otherwise by law to which we are subject. Where a law requires us to process beyond your instructions, we will inform you of that requirement before processing, unless the law prohibits it on important grounds of public interest.

Your instructions are:

  • This agreement and the main agreement.
  • The configuration you set in the console — sites, masking rules, body capture, consent gating, retention, AI features and regions.
  • Any further written instruction you give us.

We will tell you if, in our opinion, an instruction infringes Data Protection Law. We are not obliged to carry out an infringing instruction.

3. Confidentiality

Every person we authorise to process personal data is bound by a duty of confidentiality that survives the end of their engagement. Access is limited to those who need it to operate or support the service.

Staff access to customer data through administrative interfaces is recorded in an append-only audit log, enforced at the database level rather than by convention, so a new administrative route cannot omit it.

4. Security

We implement appropriate technical and organisational measures under Article 32, described in Annex II. Those measures reflect the state of the art, the cost of implementation, and the nature, scope, context and purposes of the processing, against the risk to data subjects.

We may update the measures over time. We will not make a change that materially reduces the overall level of protection.

5. Sub-processors

You give general written authorisation for us to engage sub-processors. The current list is in Annex III.

We impose on every sub-processor, by written contract, data protection obligations no less protective than those in this agreement. We remain fully liable to you for a sub-processor’s performance.

We will give you at least 30 days’ notice before adding or replacing a sub-processor. You may object on reasonable data protection grounds within that period. If we cannot resolve the objection, you may terminate the affected part of the service without penalty, and we will refund prepaid fees for the unused term.

6. Data subject rights

Taking into account the nature of the processing, we assist you by appropriate technical and organisational measures to respond to data subject requests under Chapter III.

The service provides controller-operated endpoints for subject access and portability (structured export), erasure, and a record of requests handled. Erasure runs through the same deletion path as retention, so a subject erasure cannot drift from the behavior we document elsewhere: it removes the database rows and sweeps the object-storage prefix for that tenant.

We do not answer data subjects directly

These are deliberately not public endpoints a data subject calls. You hold the relationship with the data subject and verify their identity; you then instruct us. That is the division Article 28(3)(e) contemplates — the processor assists, it does not answer on the controller’s behalf. If a data subject contacts us directly, we will not respond substantively; we will refer them to you and tell you promptly.

7. Personal data breach

We notify you without undue delay after becoming aware of a personal data breach affecting personal data we process for you, and in any event in time to let you meet your own 72-hour obligation under Article 33.

Our notification will describe, so far as known at the time:

  • the nature of the breach, including the categories and approximate number of data subjects and records concerned;
  • the likely consequences;
  • the measures taken or proposed to address it and to mitigate its effects;
  • a contact point for further information.

Where we cannot provide all of it at once, we will provide it in phases without further undue delay. We will not represent to any third party that a breach originated with you without your prior agreement, unless required by law.

8. Impact assessments

We provide reasonable assistance with your data protection impact assessments and any prior consultation with a supervisory authority under Articles 35 and 36, taking into account the nature of the processing and the information available to us.

Session replay usually requires a DPIA

Recording user sessions is, in most deployments, systematic monitoring on a large scale within Article 35(3)(c). You should assume a DPIA is required for your use of the service and complete one before you begin recording, rather than treating it as optional. We will support yours with the technical detail it needs.

9. Deletion and return

On termination, and at your choice, we delete or return all personal data processed on your behalf and delete existing copies, unless law requires storage.

You can export your data through the API at any time during the term. Absent a written instruction to return it, we delete it within 30 days of termination. Deletion covers database records and the corresponding object-storage prefixes. Where an individual object deletion fails, it is recorded and retried until it succeeds; the obligation is not treated as lapsing because an attempt failed.

Backups are overwritten on their ordinary cycle. Personal data persisting only in backup remains subject to this agreement until it is overwritten.

10. Audits and information

We make available to you the information necessary to demonstrate compliance with Article 28 and allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate.

In practice:

  1. We respond to security questionnaires and written requests for information about the measures in Annex II.
  2. Where we hold a current third-party audit report or certification, we provide it under NDA, and it satisfies the request where it covers the scope in question.
  3. Where it does not, you may conduct an audit on reasonable prior notice, no more than once in any 12-month period unless required by a supervisory authority or following a personal data breach, during business hours, subject to confidentiality, and without access to other customers’ data or to systems whose exposure would weaken security for every customer.

We do not currently hold SOC 2 or ISO 27001

We would rather say so than imply otherwise. Requests are answered directly, with evidence, by the engineers who built the control being asked about.

11. International transfers

Personal data is processed in the United States. Annex I records the processing locations. We do not currently offer an EU processing region.

Where you transfer personal data subject to the GDPR to us, the Standard Contractual Clauses in Commission Implementing Decision (EU) 2021/914, Module Two (controller to processor), apply and are incorporated into this agreement by reference. You are the data exporter; we are the data importer. Clause 7 (docking) applies; Clause 9 option 2 (general authorisation) applies with the 30-day notice period in section 5; Clause 11 optional redress does not apply; Clauses 17 and 18 take the law and forum below. Annexes I, II and III of this agreement populate Annexes I, II and III of the Clauses.

We will notify you if we become subject to a law that prevents us from meeting these obligations, and will challenge any public-authority request for personal data we process for you where there are lawful grounds to do so, disclosing only the minimum permissible if we must comply.

Assess this honestly before you record EU users

There is no EU region today. If your processing requires that personal data does not leave the EEA, this service does not meet that requirement, and the Clauses do not change it. Read this section as a description of a real limitation rather than as reassurance.

12. Liability, term and governing law

Each party’s liability under this agreement is subject to the limitations and exclusions of liability in the main agreement. Nothing here limits a data subject’s rights under Article 82 or either party’s liability to a supervisory authority.

This agreement takes effect when you begin using the service and continues for as long as we process personal data on your behalf. Sections 3, 7, 9, 10 and 11 survive termination to the extent processing continues.

This agreement is governed by the law of the Commonwealth of Virginia, United States, and the courts of that jurisdiction have exclusive jurisdiction, except that the Standard Contractual Clauses are governed as stated in them.

Annex I — Description of the processing

A. Parties

RoleParty
Controller / exporterThe customer identified in the main agreement, at the address given in their account.
Processor / importerSiddi Tek LLC, 41551 Bostonian Place, Aldie, VA 20105, United States. Contact: [email protected].
EU representative (Art. 27)[EU REPRESENTATIVE, IF APPOINTED]

B. Description

Subject matterProvision of session replay, application and infrastructure monitoring, logging and uptime monitoring.
DurationThe term of the main agreement, plus the deletion window in section 9.
Nature and purposeCollection, storage, structuring, analysis and display of product-analytics and telemetry data so the controller can understand how its own application behaves and how its users experience it.
Categories of data subjectVisitors and end users of the controller’s websites and applications; the controller’s own personnel who use the console.
Categories of personal data
  • Online identifiers: a first-party visitor identifier, session identifier, truncated IP address, user agent, device and browser characteristics, approximate location derived from a truncated IP.
  • Behavioural data: page URLs with query strings redacted, page titles, DOM mutations reconstructing the rendered page, clicks, scrolls, navigation and custom events.
  • Technical data: console output, network request and response metadata, error messages and stack traces, performance timings, traces, logs and host metrics.
  • Identity the controller chooses to send: a user identifier and arbitrary metadata attached by the controller, which may include a name or email address if the controller sends one.
  • Console account data: email address, optional name and phone number, hashed password, role and access grants.
Input values are masked in the page before a payload exists. Password fields are masked unconditionally. Request and response bodies are not captured unless the controller enables it per site.
Special category dataNot intentionally processed. The service is not designed for it and the controller should not configure capture in a way that collects it. Masking defaults, unconditional password masking and opt-in body capture exist to keep it out.
Children’s dataNot knowingly processed. The service has no age verification; the controller must not deploy it where it would collect children’s data without an appropriate basis.
FrequencyContinuous, for as long as the controller’s instrumentation is deployed.
RetentionSet by the controller’s plan and configuration, from 14 days on the free plan. Retention is enforced by an automated mark-and-purge process, not by manual cleanup. Console account data is retained for the term of the agreement.
Processing locationsApplication, database and object storage in New York, United States (DigitalOcean nyc3). Sub-processors process in the locations stated in Annex III.

C. Competent supervisory authority

The supervisory authority of the EEA member state in which the controller is established, or where the controller is not established in the EEA, the authority of the member state in which its Article 27 representative is established.

Annex II — Technical and organisational measures

These are the measures in force. They are drawn from the same technical audit we maintain internally, so that this annex and the system it describes cannot diverge quietly.

Minimisation at capture

  • Input values are masked in the page, before a network payload is constructed. The value never enters the payload, so it is not in transit and not in storage.
  • Password fields are masked unconditionally, including where masking is otherwise disabled.
  • Authorization, Cookie and Set-Cookie headers are stripped with no setting to re-enable them.
  • URL query strings and value-bearing fragments are redacted before storage, on entry URLs and page views alike.
  • Page titles and console arguments run through a PII-masking pipeline covering email addresses, card-like numbers, national identifier patterns and long digit runs.
  • Request and response bodies are not captured by default; body capture is opt-in per site and masked when enabled.
  • Controllers can name their own sensitive keys, masked on the device in bodies, WebSocket frames, console arguments and custom event properties.
  • Global Privacy Control and Do Not Track stop recording before any configuration is considered, emitting no network calls at all.
  • Consent gating defaults to required for visitors in the EEA, determined by device time zone. With consent withheld the SDK starts nothing and emits zero requests.

Encryption

  • In transit: TLS for all public endpoints. Database connections use TLS by default for any non-loopback host, with certificate verification available; verified at TLS 1.3.
  • At rest: server-side AES-256 encryption requested explicitly on every object written to storage, rather than relying on a provider default.
  • Secrets for authenticated uptime checks are encrypted with AES-256-GCM and referenced by name, never echoed back.
  • Console passwords are stored as scrypt hashes. Secret API keys are stored only as SHA-256 hashes and cannot be redisplayed.

Access control and isolation

  • Every record carries a tenant and site identifier, and the API derives the tenant from the credential and scopes every query to it.
  • Role-based access — owner, admin, member, viewer — with per-site grants, so access can be narrowed to a single site.
  • Two key types: publishable ingest keys that can only write and are scoped and rate-limited, and secret server keys that can read.
  • Replay data is held in a private bucket and served only through the authenticated API; the bucket requires no public access.
  • Administrative access to customer data is recorded in an append-only log enforced by database trigger at the single point every administrative route passes through.

Deletion and retention

  • Retention is enforced automatically per tenant entitlement by a mark phase and a trickle purge, not by manual intervention.
  • Deletion covers database rows, partitioned event tables, mobile frames and foreign-key cascades, with non-cascading tables handled explicitly.
  • Object deletion is a tenant-namespaced prefix sweep. A failed deletion is recorded before the database row is removed — after which the prefix would be unreconstructable — and retried with backoff indefinitely.

Limits on automated analysis

  • AI features are gated per tenant and fail closed: if the flag cannot be read, the feature is off, so an outage cannot be treated as consent.
  • Analysis of rendered mobile screens by a vision model is off by default and must be opted into explicitly.
  • The AI layer is never given database access and cannot write queries. It narrates results returned by parameterised queries.
  • IP addresses are truncated to a /24 (IPv4) or /48 (IPv6) before any geolocation lookup leaves our systems, so a full address is never disclosed to that sub-processor.

Measures we do not yet have

Listed because their absence is material to a risk assessment, and a security reviewer will find them anyway:

  • No SOC 2 or ISO 27001 certification.
  • No EU processing region; see section 11.
  • Multi-factor authentication on console accounts is not yet available.

Annex III — Authorised sub-processors

The sub-processors engaged as at the effective date. Changes are notified under section 5.

Sub-processorPurposeLocation
DigitalOcean, LLCApplication hosting, managed database, object storage and CDN origin. Processes all categories of data in Annex I.United States
Cloudflare, Inc.CDN and DNS in front of the script bundle host. Processes request metadata only.Global edge network
Stripe, Inc.Subscription billing for console accounts. Processes billing contact and payment data, not end-user telemetry.United States
Resend (Plus Five Five, Inc.)Transactional and alert email to console users. Processes console account email addresses and names.United States
OpenAI, L.L.C.Optional AI narration and analysis. Processes only the telemetry passed for a requested analysis, and only where the tenant has enabled AI features.United States
Anthropic PBCOptional AI narration and analysis, as an alternative provider. Same scope as above.United States
freeipapiApproximate geolocation from a network prefix. Receives only a truncated IP address, never a full one.United States

Contact

Data protection enquiries, DSAR instructions and notices under this agreement: [email protected].

Suspected vulnerabilities or security incidents: [email protected].

If you need this executed as a countersigned document, or you require changes for your own compliance position, contact us at [email protected] and we will work through it.