This DPA describes how Thexly, operated by Thexly Limited, processes personal data on your behalf when you use Thexly to collect analytics or revenue-attribution data from your website's visitors, or from your own clients if you're an agency. For the purposes of this agreement, you are the data controller and Thexly is the data processor.
1. Roles
You, the Thexly account holder, are the data controller of the personal data belonging to your website visitors and, if you're an agency, your own clients. Thexly is the data processor, processing that data only on your documented instructions and only to provide the service.
2. Subject matter and duration
Thexly processes personal data for the duration of your subscription, for the purpose of providing web analytics, revenue attribution, and, if connected, Search-Console-based search insights. Processing ends when your account is closed, subject to the retention periods in the Privacy Policy.
3. Nature and purpose of processing
- Capturing page views, referrer/UTM/click-ID data, custom events, and technical session context (browser, OS, device, approximate location) from your website visitors, without cookies or persistent identifiers
- If enabled, recording on-page interactions for session replay, reconstructed from DOM structure rather than video
- Matching payments from your connected payment processor to the sessions that produced them
- Where connected, modeling revenue against Google Search Console query data
4. Categories of data subjects and data
Data subjects: visitors to your website, and, if you're an agency, the end customers of the client sites you manage through Thexly.
Categories of data:
- Technical/session data (browser, OS, device, approximate location, page interactions), not tied to an identified person under normal use
- Where a connected payment provider exposes a payer's email address, Thexly converts it to a one-way hash before storing it, alongside the provider's own transaction/customer identifiers and the payment amount and currency, never plaintext email, name, or card data
- Any identifier or property you choose to pass via the tracking script's
identify()function, you control what this contains, so you are responsible for its lawfulness
5. Processor obligations
Thexly will: process personal data only on your documented instructions; ensure personnel with access are bound by confidentiality; implement appropriate technical and organizational security measures; assist you in responding to data subject rights requests and regulator inquiries relating to the processing; notify you without undue delay, and no later than 48 hours, after becoming aware of a personal data breach affecting your data, so you can meet your own regulatory notification obligations; and delete or return personal data at the end of the relationship, except where retention is required by law.
6. Sub-processors
You authorize Thexly to engage the following sub-processors to provide the service: Vercel (application hosting), Neon (database hosting), Clerk (authentication), Stripe (Thexly's own billing), and Zoho Mail (email delivery). If you connect a payment provider (Stripe, Lemon Squeezy, Polar, Dodo Payments, Yolfi) or Google Search Console, that provider processes data as your own instructed sub-processor, not Thexly's. Thexly will notify you of new sub-processors and give a reasonable objection period, length to be confirmed and stated here, before they go live.
7. Security measures
Encryption in transit and at rest, access to personal data limited to what's needed to operate the service, and no cookies or persistent visitor identifiers by design, which meaningfully reduces the personal-data footprint compared to typical analytics tools. Additional specific measures (e.g. access logging, staff access controls) will be listed here before this is final.
8. Assistance with data subject rights
Thexly will help you respond to a data subject's request to access, correct, delete, or export their data, to the extent that request relates to data Thexly processes on your behalf.
9. International transfers
Thexly's infrastructure is being migrated to an EU region (West Europe) ahead of this agreement going live. Where personal data is processed outside the EEA/UK, an appropriate transfer mechanism (such as Standard Contractual Clauses) will apply. This section will name the specific mechanism and sub-processor locations once that migration is confirmed.
10. Deletion or return of data
On termination of your account, Thexly will delete personal data processed on your behalf within 30 days, except where retention is required by law (e.g. billing records).
11. Audit rights
You may request information reasonably necessary to demonstrate Thexly's compliance with this DPA. Whether this extends to on-site audit rights, or is limited to documentation on request, will be decided and stated here before this is final.
12. Liability and governing law
This DPA is governed by the same law as the main Terms of Service and is subject to the liability terms there.
Contact
Questions about this DPA? Contact support@thexly.com.