Last updated September 10, 2026
Data processing agreement
How Tracwell processes customer analytics on your instructions.
Scope and instructions
Tracwell is operated by Saurabh Chauhan, an independent operator based in India. References to Tracwell, we, or us mean Saurabh Chauhan operating the service.
This agreement forms part of the service terms when you accept them and applies where we process personal data on your behalf. It prevails on conflicts about processing customer personal data. The customer acts as controller, or as a processor authorized by its controller; Tracwell acts as processor or subprocessor respectively.
Processing covers collection, validation, storage, querying, export, and deletion of website and app analytics for the service period and the documented deletion and backup lifecycle. Data subjects are visitors, users, and purchasing customers. Data includes pseudonymous IDs, URLs, referrers, device and location information, event properties, timestamps, and payment-event references and amounts. Sensitive categories are not intended.
The customer determines purposes, lawful basis, collection settings, notices, consent, and authorized users. Documented instructions consist of this agreement, service settings, and agreed written requests. Tracwell will process only on those instructions, including transfers, unless required by law; it will notify the customer before legally required processing unless prohibited, and promptly flag instructions it considers unlawful.
Confidentiality and security
Tracwell will limit access to authorized people under confidentiality obligations and use measures appropriate to risk: encrypted transport, scoped credentials, access controls, tenant isolation, audit records, backup protections, and recovery procedures. It will maintain and assess those measures and assist with security obligations considering the processing and information available.
No raw IP storage in analytics by default, daily Private-mode identifiers, property limits, and configurable retention reduce exposure. Customers remain responsible for minimizing their event payloads and protecting their credentials.
Subprocessors and transfers
By accepting this agreement, the customer gives general written authorization for infrastructure subprocessors in the provider register. Tracwell will give at least 30 days’ advance notice of additions or replacements, allowing objections on reasonable data-protection grounds. If unresolved, the parties will stop the affected processing and arrange return or deletion.
Tracwell will impose equivalent data-protection obligations on subprocessors and remain responsible for their performance. Personal data will be transferred internationally only on documented instructions and with an applicable Chapter V mechanism and any required supplementary safeguards. This agreement does not incorporate or replace transfer Standard Contractual Clauses; the appropriate terms and annexes must be completed where required.
Rights, incidents, and assistance
Tracwell will forward relevant visitor requests to the customer and assist with access, correction, erasure, restriction, portability, and objections through appropriate technical and organizational measures. It will not independently answer on the customer’s behalf unless authorized or legally required.
Tracwell will notify the customer without undue delay after becoming aware of a personal data breach, providing available details of affected data, likely consequences, mitigation, and a contact, with updates as facts become available. The customer decides its regulatory and visitor notifications.
Tracwell will assist with data protection impact assessments and prior consultation where applicable, considering the nature of processing and information available.
Return, deletion, and review
At the customer’s choice, Tracwell will return or delete customer personal data after the service ends and delete existing copies unless law requires storage. Customers can export available retained events. Isolated backups expire under the disclosed lifecycle; until then, processing is limited to protection and recovery, with deletion instructions reapplied before data is made available again.
Tracwell will provide information needed to demonstrate its obligations and allow and contribute to audits, including inspections, by the customer or an authorized independent auditor. Reasonable confidentiality and scheduling arrangements must not prevent legally required oversight.
Contact
For questions or requests, contact saurabh10102@gmail.com.