Zensli
  • Home
  • About
  • Pricing & FAQ
  • Contact
  • API Docs ↗
    • Data Processing Agreement
    • Privacy Policy
    • Terms of Service
  • Login
Login Start Free
Legal agreement

Zensli Data Processing Agreement

This agreement explains how personal data is processed, protected, and managed when customers use the Zensli service.

PKG AB Sweden GDPR Data Processor

Agreement contents

Introduction Definitions Nature and Purpose Categories of Data Processor Obligations Customer Obligations Technical Measures Liability and Indemnity Duration and Termination Appendix 1 Privacy Policy

This Data Processing Agreement (“DPA”) governs how PKG AB, a Swedish company (Reg. No. SE559008922201), hereafter referred to as the “Service Provider,” “we,” “us,” or “our,” processes personal data on behalf of its Customers in connection with providing the Zensli service.

1 Introduction

This DPA forms part of the agreement between the Customer and the Service Provider for use of the Zensli service.

The purpose of this DPA is to define the respective responsibilities of the parties when the Service Provider processes personal data on behalf of the Customer.

2 Definitions

Customer
The organisation using the Zensli Service.
Service
The Zensli service provided by the Service Provider to collect and analyse online behaviour of the Customer’s website visitors or application users.
Data Protection Legislation
The General Data Protection Regulation (GDPR), Regulation (EU) 2016/679, and all other applicable laws relating to the processing of personal data and privacy.
Data protection terms
Data Controller, Data Processor, Data Subject, Personal Data, Processing, and Appropriate Technical and Organisational Measures shall be interpreted according to the definitions in applicable Data Protection Legislation.
Roles of the parties

The parties acknowledge that the Customer is the Data Controller and the Service Provider is the Data Processor with respect to personal data processed through the Service.

3 Nature and Purpose of Processing

Personal data is processed solely for statistical evaluation and analysis of performance and usage behaviour of individuals interacting with the Customer’s websites or applications.

Such processing is performed in an anonymous or pseudonymised manner where applicable. The Service Provider does not use the personal data for its own independent purposes.

4 Categories of Personal Data Processed

Depending on the Customer’s configuration of the Service, the following types of personal data may be processed:

  • IP address.
  • Geographic data, including city, region, country, and approximate latitude and longitude.
  • Browser, device type, operating system, and user agent.
  • Date, time, and time zone.
  • Pages and screens visited, including URLs and titles.
  • Referrer URL.
  • Marketing campaign URL parameters.
  • Files downloaded and external links clicked.
  • Screen resolution.
  • Session recordings, including HTML pages, mouse movements, clicks, scrolling, and keypresses, where enabled.
  • Internal search terms.
  • Custom dimensions, variables, events, and content.
  • User ID.
  • E-commerce data, including order ID, date, and abandoned carts.
  • Media titles and URLs.
  • Email addresses, phone numbers, and other personal identifiers, depending on the Customer’s configuration.

The data subjects affected are end users of the Customer’s websites and applications.

Customer responsibility

Zensli does not classify or independently determine the sensitivity of data submitted through the Service. The Customer is responsible for ensuring compliance with applicable laws, limiting the collection of sensitive data, and providing clear notice to its visitors.

Prohibited data

Credit card numbers, bank details, financial information, passwords, or any other sensitive personally identifiable information must never be sent to Zensli under any circumstances, regardless of consent obtained from end users.

All input fields within website forms that collect personally identifiable information or other sensitive data must be explicitly marked with a custom attribute such as data-type="pii".

Compliance with this requirement is mandatory to support appropriate data handling. The Customer is responsible for identifying information that visitors may consider sensitive and for implementing suitable controls.

5 Obligations of the Service Provider

  • Processing Instructions: The Service Provider shall process personal data only on documented instructions from the Customer, including instructions configured through the Service.
  • Confidentiality: The Service Provider shall protect the confidentiality of personal data and ensure that personnel authorised to process personal data are bound by confidentiality obligations.
  • Compliance with Laws: The Service Provider shall notify the Customer without undue delay if it believes that an instruction violates applicable Data Protection Legislation.
  • Data Subject Requests: If a data subject contacts the Service Provider directly, the Service Provider shall promptly forward the request to the Customer and shall not act on the request without documented instructions from the Customer, except where required by law.
  • International Transfers: Any transfer of personal data outside the EU or EEA shall require prior written consent from the Customer and shall be conducted in accordance with applicable transfer requirements under Data Protection Legislation.
  • Employee Training: The Service Provider shall ensure that personnel handling personal data receive appropriate training regarding confidentiality and data protection obligations.
  • Subprocessors: The Service Provider may engage subprocessors subject to data-protection obligations substantially similar to those in this DPA. The Customer shall be notified of material changes and may object within 30 days.
  • Incident Notification: The Service Provider shall notify the Customer without undue delay after becoming aware of a personal data breach and shall provide available information concerning the incident and mitigation measures.
  • Assistance: The Service Provider shall provide reasonable assistance to the Customer regarding applicable GDPR obligations, including breach reporting, data-protection impact assessments, and consultations with supervisory authorities.
  • Nature of Service and Limitation of Responsibility: The Service Provider acts as a technical data processor and does not create, control, verify, or independently determine the content, accuracy, lawfulness, or completeness of personal data submitted through the Service.

The Customer remains responsible for the lawful use, retention, accuracy, and integrity of data processed through the Service.

6 Customer Obligations

  • Legal Basis: The Customer represents and warrants that it has established a valid legal basis for processing, including obtaining any necessary consent, before providing personal data to the Service Provider.
  • Regulatory Compliance: The Customer shall comply with applicable privacy and data-protection laws in each jurisdiction in which its websites, applications, or services are made available.
  • Responsibility for Data Practices: The Customer is responsible for implementing and using the Zensli tracking script, integrations, and APIs in a lawful and transparent manner.
  • Data Accuracy and Limitations: The Customer acknowledges that data collected through Zensli may not always identify individuals with complete accuracy. Shared devices, inaccurate user input, or third-party contact details may result in misattribution.
  • Verification and Use: The Customer is responsible for verifying collected information before relying on it and for ensuring that such information is used lawfully.
  • Tracking Transparency and Opt-Out: The Customer must provide clear notice regarding its use of tracking technologies and offer appropriate consent and opt-out mechanisms where required by applicable law.

7 Technical and Organisational Measures

The Service Provider implements appropriate technical and organisational measures intended to protect personal data in accordance with applicable Data Protection Legislation.

Access Control

Access to personal data and production environments is restricted to authorised personnel.

Encryption

HTTPS is used for data in transit, with encryption controls applied to data at rest.

Incident Detection

System activities are logged and monitored, with established incident-response procedures.

Availability

Fault-tolerant systems, redundancy, and regular backups support service availability and recovery.

Additional details are described in Appendix 1.

8 Liability and Indemnity

Each party shall indemnify and hold harmless the other party from claims, losses, damages, or liabilities arising from that party’s breach of this DPA, subject to the limitations and conditions contained in the applicable agreement between the parties.

9 Duration and Termination

This DPA becomes effective upon acceptance by the Customer and continues until termination in accordance with the Zensli Terms of Service.

Upon termination, the Service Provider shall delete personal data processed on behalf of the Customer within 30 days, unless continued retention is required by applicable law or otherwise provided for in the applicable data-retention policy.

A1 Appendix 1 – Technical and Organisational Measures

Access Control

  • Authentication and authorisation mechanisms.
  • Restricted access to production environments.
  • Employee training concerning data security, confidentiality, and privacy obligations.

Transmission and Storage Control

  • HTTPS encryption for data in transit.
  • Disk encryption for data at rest.

Incident Detection and Response

  • Logging and monitoring of relevant system activities.
  • Incident response, investigation, and tracking procedures.

Availability Control

  • Redundant systems and regular backups.
  • Testing of failover and recovery mechanisms.

10 Privacy Policy and Acceptance

For additional information about Zensli’s handling of personal data, please refer to the Zensli Privacy Policy.

By accepting this DPA, you confirm that you have the authority to bind the Customer to these terms.

If you do not have such authority, you must not accept this DPA on behalf of the Customer.

Real-time website intelligence that connects visitor behaviour, identity, dashboards, alerts, and automation with your CRM and business systems.

Privacy by design Tier 3 DC GTM-ready

Product

  • About Zensli
  • Pricing & FAQ
  • API Documentation ↗

Company

  • Contact
  • Login
  • Start Free

Legal & Privacy

  • Data Processing Agreement
  • Privacy Policy
  • Terms of Service

Questions about privacy, security, or agreements?

Contact Zensli

© 2026 Zensli . All rights reserved.

Privacy Terms
We use cookies to operate this website and, with your permission, understand usage and support marketing. See our Privacy Policy .

Cookie preferences

Choose which optional technologies may be used. Necessary storage is always enabled for security, authentication, and core functionality.

Necessary Always on

Used for security, authentication, load balancing, and storing your consent choices.

Helps us understand website usage and improve the experience.

Supports personalised campaigns and remarketing where applicable.

Loading...