This Data Processing Agreement (“DPA”) governs how PKG AB, a Swedish company (Reg. No. SE559008922201), hereafter referred to as the “Service Provider,” “we,” “us,” or “our,” processes personal data on behalf of its Customers in connection with providing the Zensli service.
1 Introduction
This DPA forms part of the agreement between the Customer and the Service Provider for use of the Zensli service.
The purpose of this DPA is to define the respective responsibilities of the parties when the Service Provider processes personal data on behalf of the Customer.
2 Definitions
- Customer
- The organisation using the Zensli Service.
- Service
- The Zensli service provided by the Service Provider to collect and analyse online behaviour of the Customer’s website visitors or application users.
- Data Protection Legislation
- The General Data Protection Regulation (GDPR), Regulation (EU) 2016/679, and all other applicable laws relating to the processing of personal data and privacy.
- Data protection terms
- Data Controller, Data Processor, Data Subject, Personal Data, Processing, and Appropriate Technical and Organisational Measures shall be interpreted according to the definitions in applicable Data Protection Legislation.
The parties acknowledge that the Customer is the Data Controller and the Service Provider is the Data Processor with respect to personal data processed through the Service.
3 Nature and Purpose of Processing
Personal data is processed solely for statistical evaluation and analysis of performance and usage behaviour of individuals interacting with the Customer’s websites or applications.
Such processing is performed in an anonymous or pseudonymised manner where applicable. The Service Provider does not use the personal data for its own independent purposes.
4 Categories of Personal Data Processed
Depending on the Customer’s configuration of the Service, the following types of personal data may be processed:
- IP address.
- Geographic data, including city, region, country, and approximate latitude and longitude.
- Browser, device type, operating system, and user agent.
- Date, time, and time zone.
- Pages and screens visited, including URLs and titles.
- Referrer URL.
- Marketing campaign URL parameters.
- Files downloaded and external links clicked.
- Screen resolution.
- Session recordings, including HTML pages, mouse movements, clicks, scrolling, and keypresses, where enabled.
- Internal search terms.
- Custom dimensions, variables, events, and content.
- User ID.
- E-commerce data, including order ID, date, and abandoned carts.
- Media titles and URLs.
- Email addresses, phone numbers, and other personal identifiers, depending on the Customer’s configuration.
The data subjects affected are end users of the Customer’s websites and applications.
Zensli does not classify or independently determine the sensitivity of data submitted through the Service. The Customer is responsible for ensuring compliance with applicable laws, limiting the collection of sensitive data, and providing clear notice to its visitors.
Credit card numbers, bank details, financial information, passwords, or any other sensitive personally identifiable information must never be sent to Zensli under any circumstances, regardless of consent obtained from end users.
All input fields within website forms that collect
personally identifiable information or other
sensitive data must be explicitly marked with a custom
attribute such as data-type="pii".
Compliance with this requirement is mandatory to support appropriate data handling. The Customer is responsible for identifying information that visitors may consider sensitive and for implementing suitable controls.
5 Obligations of the Service Provider
- Processing Instructions: The Service Provider shall process personal data only on documented instructions from the Customer, including instructions configured through the Service.
- Confidentiality: The Service Provider shall protect the confidentiality of personal data and ensure that personnel authorised to process personal data are bound by confidentiality obligations.
- Compliance with Laws: The Service Provider shall notify the Customer without undue delay if it believes that an instruction violates applicable Data Protection Legislation.
- Data Subject Requests: If a data subject contacts the Service Provider directly, the Service Provider shall promptly forward the request to the Customer and shall not act on the request without documented instructions from the Customer, except where required by law.
- International Transfers: Any transfer of personal data outside the EU or EEA shall require prior written consent from the Customer and shall be conducted in accordance with applicable transfer requirements under Data Protection Legislation.
- Employee Training: The Service Provider shall ensure that personnel handling personal data receive appropriate training regarding confidentiality and data protection obligations.
- Subprocessors: The Service Provider may engage subprocessors subject to data-protection obligations substantially similar to those in this DPA. The Customer shall be notified of material changes and may object within 30 days.
- Incident Notification: The Service Provider shall notify the Customer without undue delay after becoming aware of a personal data breach and shall provide available information concerning the incident and mitigation measures.
- Assistance: The Service Provider shall provide reasonable assistance to the Customer regarding applicable GDPR obligations, including breach reporting, data-protection impact assessments, and consultations with supervisory authorities.
- Nature of Service and Limitation of Responsibility: The Service Provider acts as a technical data processor and does not create, control, verify, or independently determine the content, accuracy, lawfulness, or completeness of personal data submitted through the Service.
The Customer remains responsible for the lawful use, retention, accuracy, and integrity of data processed through the Service.
6 Customer Obligations
- Legal Basis: The Customer represents and warrants that it has established a valid legal basis for processing, including obtaining any necessary consent, before providing personal data to the Service Provider.
- Regulatory Compliance: The Customer shall comply with applicable privacy and data-protection laws in each jurisdiction in which its websites, applications, or services are made available.
- Responsibility for Data Practices: The Customer is responsible for implementing and using the Zensli tracking script, integrations, and APIs in a lawful and transparent manner.
- Data Accuracy and Limitations: The Customer acknowledges that data collected through Zensli may not always identify individuals with complete accuracy. Shared devices, inaccurate user input, or third-party contact details may result in misattribution.
- Verification and Use: The Customer is responsible for verifying collected information before relying on it and for ensuring that such information is used lawfully.
- Tracking Transparency and Opt-Out: The Customer must provide clear notice regarding its use of tracking technologies and offer appropriate consent and opt-out mechanisms where required by applicable law.
7 Technical and Organisational Measures
The Service Provider implements appropriate technical and organisational measures intended to protect personal data in accordance with applicable Data Protection Legislation.
Access Control
Access to personal data and production environments is restricted to authorised personnel.
Encryption
HTTPS is used for data in transit, with encryption controls applied to data at rest.
Incident Detection
System activities are logged and monitored, with established incident-response procedures.
Availability
Fault-tolerant systems, redundancy, and regular backups support service availability and recovery.
Additional details are described in Appendix 1.
8 Liability and Indemnity
Each party shall indemnify and hold harmless the other party from claims, losses, damages, or liabilities arising from that party’s breach of this DPA, subject to the limitations and conditions contained in the applicable agreement between the parties.
9 Duration and Termination
This DPA becomes effective upon acceptance by the Customer and continues until termination in accordance with the Zensli Terms of Service.
Upon termination, the Service Provider shall delete personal data processed on behalf of the Customer within 30 days, unless continued retention is required by applicable law or otherwise provided for in the applicable data-retention policy.
A1 Appendix 1 – Technical and Organisational Measures
Access Control
- Authentication and authorisation mechanisms.
- Restricted access to production environments.
- Employee training concerning data security, confidentiality, and privacy obligations.
Transmission and Storage Control
- HTTPS encryption for data in transit.
- Disk encryption for data at rest.
Incident Detection and Response
- Logging and monitoring of relevant system activities.
- Incident response, investigation, and tracking procedures.
Availability Control
- Redundant systems and regular backups.
- Testing of failover and recovery mechanisms.
10 Privacy Policy and Acceptance
For additional information about Zensli’s handling of personal data, please refer to the Zensli Privacy Policy.