Legal
Data Processing Agreement
The terms under which LogClip processes personal data on your behalf, as required by Article 28 of the GDPR. It forms part of your agreement with us and applies whenever the data you send us includes personal data.
DraftVersion 1.0 · Published for review 27 August 2026
This agreement is published so you can review it before you need it. It is not yet offered for signature: the breach-notification and data-subject-request procedures it describes are being put in place. Ask us for the current signable version.
Read this alongside the product, not instead of it
1. Scope and roles
You are the controller. You decide what to record, on which sites, with what masking, and for how long. You determine the purposes and means of the processing.
Siddi Tek LLC is the processor. We process personal data only to provide the service to you. This agreement applies to all such processing and prevails over any conflicting term in the main agreement in respect of data protection.
“Personal data”, “controller”, “processor”, “processing”, “data subject” and “personal data breach” have the meanings given in the GDPR. “Data Protection Law” means Regulation (EU) 2016/679 and any other data protection law that applies to the processing.
2. Instructions
We process personal data only on your documented instructions, including on transfers, unless required otherwise by law to which we are subject. Where a law requires us to process beyond your instructions, we will inform you of that requirement before processing, unless the law prohibits it on important grounds of public interest.
Your instructions are:
- This agreement and the main agreement.
- The configuration you set in the console — sites, masking rules, body capture, consent gating, retention, AI features and regions.
- Any further written instruction you give us.
We will tell you if, in our opinion, an instruction infringes Data Protection Law. We are not obliged to carry out an infringing instruction.
3. Confidentiality
Every person we authorise to process personal data is bound by a duty of confidentiality that survives the end of their engagement. Access is limited to those who need it to operate or support the service.
Staff access to customer data through administrative interfaces is recorded in an append-only audit log, enforced at the database level rather than by convention, so a new administrative route cannot omit it.
4. Security
We implement appropriate technical and organisational measures under Article 32, described in Annex II. Those measures reflect the state of the art, the cost of implementation, and the nature, scope, context and purposes of the processing, against the risk to data subjects.
We may update the measures over time. We will not make a change that materially reduces the overall level of protection.
5. Sub-processors
You give general written authorisation for us to engage sub-processors. The current list is in Annex III.
We impose on every sub-processor, by written contract, data protection obligations no less protective than those in this agreement. We remain fully liable to you for a sub-processor’s performance.
We will give you at least 30 days’ notice before adding or replacing a sub-processor. You may object on reasonable data protection grounds within that period. If we cannot resolve the objection, you may terminate the affected part of the service without penalty, and we will refund prepaid fees for the unused term.
6. Data subject rights
Taking into account the nature of the processing, we assist you by appropriate technical and organisational measures to respond to data subject requests under Chapter III.
The service provides controller-operated endpoints for subject access and portability (structured export), erasure, and a record of requests handled. Erasure runs through the same deletion path as retention, so a subject erasure cannot drift from the behavior we document elsewhere: it removes the database rows and sweeps the object-storage prefix for that tenant.
We do not answer data subjects directly
7. Personal data breach
We notify you without undue delay after becoming aware of a personal data breach affecting personal data we process for you, and in any event in time to let you meet your own 72-hour obligation under Article 33.
Our notification will describe, so far as known at the time:
- the nature of the breach, including the categories and approximate number of data subjects and records concerned;
- the likely consequences;
- the measures taken or proposed to address it and to mitigate its effects;
- a contact point for further information.
Where we cannot provide all of it at once, we will provide it in phases without further undue delay. We will not represent to any third party that a breach originated with you without your prior agreement, unless required by law.
8. Impact assessments
We provide reasonable assistance with your data protection impact assessments and any prior consultation with a supervisory authority under Articles 35 and 36, taking into account the nature of the processing and the information available to us.
Session replay usually requires a DPIA
9. Deletion and return
On termination, and at your choice, we delete or return all personal data processed on your behalf and delete existing copies, unless law requires storage.
You can export your data through the API at any time during the term. Absent a written instruction to return it, we delete it within 30 days of termination. Deletion covers database records and the corresponding object-storage prefixes. Where an individual object deletion fails, it is recorded and retried until it succeeds; the obligation is not treated as lapsing because an attempt failed.
Backups are overwritten on their ordinary cycle. Personal data persisting only in backup remains subject to this agreement until it is overwritten.
10. Audits and information
We make available to you the information necessary to demonstrate compliance with Article 28 and allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate.
In practice:
- We respond to security questionnaires and written requests for information about the measures in Annex II.
- Where we hold a current third-party audit report or certification, we provide it under NDA, and it satisfies the request where it covers the scope in question.
- Where it does not, you may conduct an audit on reasonable prior notice, no more than once in any 12-month period unless required by a supervisory authority or following a personal data breach, during business hours, subject to confidentiality, and without access to other customers’ data or to systems whose exposure would weaken security for every customer.
We do not currently hold SOC 2 or ISO 27001
11. International transfers
Personal data is processed in the United States. Annex I records the processing locations. We do not currently offer an EU processing region.
Where you transfer personal data subject to the GDPR to us, the Standard Contractual Clauses in Commission Implementing Decision (EU) 2021/914, Module Two (controller to processor), apply and are incorporated into this agreement by reference. You are the data exporter; we are the data importer. Clause 7 (docking) applies; Clause 9 option 2 (general authorisation) applies with the 30-day notice period in section 5; Clause 11 optional redress does not apply; Clauses 17 and 18 take the law and forum below. Annexes I, II and III of this agreement populate Annexes I, II and III of the Clauses.
We will notify you if we become subject to a law that prevents us from meeting these obligations, and will challenge any public-authority request for personal data we process for you where there are lawful grounds to do so, disclosing only the minimum permissible if we must comply.
Assess this honestly before you record EU users
12. Liability, term and governing law
Each party’s liability under this agreement is subject to the limitations and exclusions of liability in the main agreement. Nothing here limits a data subject’s rights under Article 82 or either party’s liability to a supervisory authority.
This agreement takes effect when you begin using the service and continues for as long as we process personal data on your behalf. Sections 3, 7, 9, 10 and 11 survive termination to the extent processing continues.
This agreement is governed by the law of the Commonwealth of Virginia, United States, and the courts of that jurisdiction have exclusive jurisdiction, except that the Standard Contractual Clauses are governed as stated in them.
Annex I — Description of the processing
A. Parties
| Role | Party |
|---|---|
| Controller / exporter | The customer identified in the main agreement, at the address given in their account. |
| Processor / importer | Siddi Tek LLC, 41551 Bostonian Place, Aldie, VA 20105, United States. Contact: [email protected]. |
| EU representative (Art. 27) | [EU REPRESENTATIVE, IF APPOINTED] |
B. Description
| Subject matter | Provision of session replay, application and infrastructure monitoring, logging and uptime monitoring. |
| Duration | The term of the main agreement, plus the deletion window in section 9. |
| Nature and purpose | Collection, storage, structuring, analysis and display of product-analytics and telemetry data so the controller can understand how its own application behaves and how its users experience it. |
| Categories of data subject | Visitors and end users of the controller’s websites and applications; the controller’s own personnel who use the console. |
| Categories of personal data |
|
| Special category data | Not intentionally processed. The service is not designed for it and the controller should not configure capture in a way that collects it. Masking defaults, unconditional password masking and opt-in body capture exist to keep it out. |
| Children’s data | Not knowingly processed. The service has no age verification; the controller must not deploy it where it would collect children’s data without an appropriate basis. |
| Frequency | Continuous, for as long as the controller’s instrumentation is deployed. |
| Retention | Set by the controller’s plan and configuration, from 14 days on the free plan. Retention is enforced by an automated mark-and-purge process, not by manual cleanup. Console account data is retained for the term of the agreement. |
| Processing locations | Application, database and object storage in New York, United States (DigitalOcean nyc3). Sub-processors process in the locations stated in Annex III. |
C. Competent supervisory authority
The supervisory authority of the EEA member state in which the controller is established, or where the controller is not established in the EEA, the authority of the member state in which its Article 27 representative is established.
Annex II — Technical and organisational measures
These are the measures in force. They are drawn from the same technical audit we maintain internally, so that this annex and the system it describes cannot diverge quietly.
Minimisation at capture
- Input values are masked in the page, before a network payload is constructed. The value never enters the payload, so it is not in transit and not in storage.
- Password fields are masked unconditionally, including where masking is otherwise disabled.
- Authorization, Cookie and Set-Cookie headers are stripped with no setting to re-enable them.
- URL query strings and value-bearing fragments are redacted before storage, on entry URLs and page views alike.
- Page titles and console arguments run through a PII-masking pipeline covering email addresses, card-like numbers, national identifier patterns and long digit runs.
- Request and response bodies are not captured by default; body capture is opt-in per site and masked when enabled.
- Controllers can name their own sensitive keys, masked on the device in bodies, WebSocket frames, console arguments and custom event properties.
- Global Privacy Control and Do Not Track stop recording before any configuration is considered, emitting no network calls at all.
- Consent gating defaults to required for visitors in the EEA, determined by device time zone. With consent withheld the SDK starts nothing and emits zero requests.
Encryption
- In transit: TLS for all public endpoints. Database connections use TLS by default for any non-loopback host, with certificate verification available; verified at TLS 1.3.
- At rest: server-side AES-256 encryption requested explicitly on every object written to storage, rather than relying on a provider default.
- Secrets for authenticated uptime checks are encrypted with AES-256-GCM and referenced by name, never echoed back.
- Console passwords are stored as scrypt hashes. Secret API keys are stored only as SHA-256 hashes and cannot be redisplayed.
Access control and isolation
- Every record carries a tenant and site identifier, and the API derives the tenant from the credential and scopes every query to it.
- Role-based access — owner, admin, member, viewer — with per-site grants, so access can be narrowed to a single site.
- Two key types: publishable ingest keys that can only write and are scoped and rate-limited, and secret server keys that can read.
- Replay data is held in a private bucket and served only through the authenticated API; the bucket requires no public access.
- Administrative access to customer data is recorded in an append-only log enforced by database trigger at the single point every administrative route passes through.
Deletion and retention
- Retention is enforced automatically per tenant entitlement by a mark phase and a trickle purge, not by manual intervention.
- Deletion covers database rows, partitioned event tables, mobile frames and foreign-key cascades, with non-cascading tables handled explicitly.
- Object deletion is a tenant-namespaced prefix sweep. A failed deletion is recorded before the database row is removed — after which the prefix would be unreconstructable — and retried with backoff indefinitely.
Limits on automated analysis
- AI features are gated per tenant and fail closed: if the flag cannot be read, the feature is off, so an outage cannot be treated as consent.
- Analysis of rendered mobile screens by a vision model is off by default and must be opted into explicitly.
- The AI layer is never given database access and cannot write queries. It narrates results returned by parameterised queries.
- IP addresses are truncated to a /24 (IPv4) or /48 (IPv6) before any geolocation lookup leaves our systems, so a full address is never disclosed to that sub-processor.
Measures we do not yet have
Listed because their absence is material to a risk assessment, and a security reviewer will find them anyway:
- No SOC 2 or ISO 27001 certification.
- No EU processing region; see section 11.
- Multi-factor authentication on console accounts is not yet available.
Annex III — Authorised sub-processors
The sub-processors engaged as at the effective date. Changes are notified under section 5.
| Sub-processor | Purpose | Location |
|---|---|---|
| DigitalOcean, LLC | Application hosting, managed database, object storage and CDN origin. Processes all categories of data in Annex I. | United States |
| Cloudflare, Inc. | CDN and DNS in front of the script bundle host. Processes request metadata only. | Global edge network |
| Stripe, Inc. | Subscription billing for console accounts. Processes billing contact and payment data, not end-user telemetry. | United States |
| Resend (Plus Five Five, Inc.) | Transactional and alert email to console users. Processes console account email addresses and names. | United States |
| OpenAI, L.L.C. | Optional AI narration and analysis. Processes only the telemetry passed for a requested analysis, and only where the tenant has enabled AI features. | United States |
| Anthropic PBC | Optional AI narration and analysis, as an alternative provider. Same scope as above. | United States |
| freeipapi | Approximate geolocation from a network prefix. Receives only a truncated IP address, never a full one. | United States |
Contact
Data protection enquiries, DSAR instructions and notices under this agreement: [email protected].
Suspected vulnerabilities or security incidents: [email protected].
If you need this executed as a countersigned document, or you require changes for your own compliance position, contact us at [email protected] and we will work through it.
