Data Processing Agreement
Última actualización: September 5, 2026
This Data Processing Agreement (the "DPA") applies when you let tobecited count the visits your website receives from AI assistants. It covers one feature: the tobecited visitor tag — the one-line script you place on your own website. For that feature, and only for that feature, you are the controller and we are your processor. The DPA forms part of the Terms of Service and takes effect when you install the tag; you do not need to sign a separate copy, although we will sign one on request. It is written to satisfy Article 28 of the EU General Data Protection Regulation (GDPR) and its UK equivalent.
1. Which data this covers, and which it does not
This DPA covers only the visit signals we receive from your website through our tag. For everything else the Service does — your account, your projects, your reports, the audits and monitoring we run for you — we are the controller and act for our own purposes, as described in our Privacy Policy at https://tobecited.com/privacy. Those two roles do not mix, and nothing in this DPA gives us permission to use visitor signals from your site for our own purposes.
2. Subject matter, duration, nature and purpose
- Subject matter and nature of processing: receiving a single request from a visitor’s browser when that visitor arrives at your website from another website, determining from the referring address whether the visit came from an AI assistant, and adding it to a daily count.
- Purpose: showing you, in your tobecited account, how many visits your website receives from AI assistants and which pages they land on. No other purpose is permitted under this DPA.
- Duration: for as long as your account exists and the tag is installed. Daily counts are deleted automatically 730 days after the day they describe.
- Categories of data subjects: visitors to your website who arrive from another website.
- Categories of personal data: none is stored. What we store per visit is described below, and it contains no identifier of the visitor. The visitor’s IP address is visible to our servers in transit, as it is for any web request, and is used only to deliver the response and to apply rate limits; it is not written to our access logs, not stored, and not linked to anything.
- Special categories of data: none. The tag must not be placed on pages whose address itself reveals special-category data about the visitor — see "Your instructions and your responsibilities".
3. What is actually stored
We store daily aggregates and nothing else. One row is: your project, the date (UTC), the assistant the visit came from, the path of the landing page, and a counter. Individual events are never written to our database — they are counted in memory and added to the daily row. Above a fixed number of distinct landing pages per website per day, further pages are recorded as “other” instead of by address; the visits themselves are still counted in full.
The tag writes nothing to the visitor’s device: no cookies, no localStorage, no sessionStorage, no device fingerprint. It sends us the referring address, the campaign parameter of the link if there is one, and the path of the page — never the full query string, because on other people’s websites query strings carry email addresses, session and order identifiers. We do not count unique visitors, and we could not: doing so without storage would require hashing the visitor’s address, and we do not do that. We count visits, and we call them visits.
Because nothing is written to the visitor’s device and no identifier is stored, the tag does not require visitor consent under Article 5(3) of the ePrivacy Directive, and it does not oblige you to add a cookie banner. This is a commitment, not a description of today’s configuration: if that ever ceased to be true, we would tell you before it changed.
4. Your instructions and your responsibilities
We process visitor data only on your documented instructions. Installing the tag is your instruction to carry out the processing described in this DPA; the settings in your account, and any further instruction you send us in writing at support@tobecited.com, are the rest of it. If we believe an instruction infringes data protection law, we will tell you and may suspend that processing until it is resolved. We will not process visitor data outside your instructions except where law requires it, in which case we will inform you first unless the law forbids that.
- You are responsible for the lawfulness of the processing on your own website, including your privacy notice. Ready-made wording you can paste into it is shown next to the tag in your account.
- You must not place the tag on pages whose path reveals sensitive information about the visitor — for example a page address containing a medical condition, a person’s name or an order identifier. We store the path, and we have no way of knowing what your paths mean.
- You must not send us anything through the tag other than what it sends by itself. The tag is served by us and its behaviour is ours; a modified copy of it is not covered by this DPA.
5. Confidentiality and access
Access to production systems is restricted to the people who operate the Service, and everyone with such access is bound by an obligation of confidentiality that survives the end of their engagement. Visit counts from your website are shown to you and are never shown to another customer, sold, shared for advertising, or used to train any AI model. Where we publish research, we publish aggregated figures that identify no website and no visitor.
6. Security measures
We implement appropriate technical and organisational measures under Article 32 GDPR, taking into account that this feature stores no personal data at rest. In particular:
- Data minimisation by design: individual events are never persisted, the query string is discarded before the request leaves the visitor’s browser and again on receipt, and there is no column in our database that could hold an address, an identifier or a fingerprint.
- All traffic is encrypted in transit (TLS).
- Requests to the tag endpoint are rate-limited and are excluded from our access logs, so visitor addresses are not written to disk.
- Servers and database are hosted in the European Union, with access restricted to named administrators using key-based authentication and multi-factor authentication where the provider supports it.
- Database backups are encrypted before they leave the server and stored off-site with access restricted to the operator; daily counts contained in them are subject to the same retention as the live data.
- Changes to the Service go through automated tests and review before release, including tests that assert what the tag sends and what is stored.
7. Sub-processors
You give us general authorisation to engage sub-processors for this feature. Each is engaged under a written contract imposing the same obligations as this DPA, and we remain fully liable to you for their performance. For visitor data the current sub-processors are:
- Our hosting provider in the European Union (currently OVH, France), which hosts the servers and database that receive and store the daily counts.
- Cloudflare, Inc., through which traffic to our domain passes for DNS, TLS termination and protection against attacks. Visitor requests transit Cloudflare; nothing about them is stored there for us.
- An off-site storage provider (currently Google) holding encrypted backups of our database, which include the daily counts.
No AI provider and no email provider receives visitor data from your website: the assistants named in your reports are queried by us with our own questions and never receive anything about your visitors. We will notify you by email at least 30 days before adding or replacing a sub-processor for this feature, and you may object on reasonable data protection grounds; if we cannot resolve the objection, you may remove the tag, and we will delete the data collected through it.
8. International transfers
Our servers and database are in the European Union, and that is where daily counts live. The only data leaving them is the encrypted backup described above. Where a sub-processor is established outside the European Economic Area, the transfer is covered by the EU Standard Contractual Clauses or another safeguard recognised under Chapter V GDPR, and we assess that safeguard before engaging the provider and when replacing one.
9. Assistance with your obligations
We will assist you, taking into account the nature of the processing and the information available to us, with data subject requests, with data protection impact assessments and prior consultations, and with your security and breach obligations under Articles 32 to 36 GDPR.
In practice this assistance is short, and the reason is worth stating plainly: because we store no identifier of any visitor, we cannot locate, export, correct or delete the data of an individual visitor on request, and neither can anyone else. If you receive such a request, we will confirm in writing what the tag collects and what is stored, so that you can answer the person accurately.
10. Personal data breaches
We will notify you without undue delay, and in any case within 48 hours, after becoming aware of a personal data breach affecting visitor data processed for you, and we will provide the information you need for your own notification obligations. We will not notify supervisory authorities or data subjects on your behalf unless you ask us to in writing.
11. Deletion and return
Daily counts are deleted automatically 730 days after the day they describe. If you delete the project or your account, everything collected for it is deleted with it. You can export the figures shown in your account at any time while it exists, and you can stop the processing at any moment by removing the tag from your website. On the end of the Service we delete visitor data within 30 days, except where law requires us to keep it, in which case we keep it only for as long as that requires and protect it as described here.
12. Information and audits
On request we will make available the information necessary to demonstrate compliance with Article 28 GDPR, and we will allow and contribute to audits, including inspections, conducted by you or an auditor you mandate. Because we are a small operator, we ask that audits be limited to once per year unless a breach or a supervisory authority requires otherwise, that they be arranged at least 30 days in advance, that they not disrupt the Service, and that the auditor be bound by confidentiality. We may satisfy an audit request by providing documentation, written answers and, where relevant, third-party certifications of our hosting provider.
13. Liability, term and precedence
This DPA is part of the Terms of Service at https://tobecited.com/terms, and the limitations of liability in those Terms apply to it, to the extent permitted by law. It takes effect when you install the tag, and ends when the processing ends and the data is deleted. If this DPA conflicts with the Terms or the Privacy Policy in respect of visitor data processed on your behalf, this DPA prevails. Where the EU Standard Contractual Clauses apply, they prevail over this DPA in the event of conflict.
14. Changes to this DPA
We may update this DPA as the feature evolves. A change is material if it introduces a new category of data we receive or store, a new purpose, a new category of sub-processor, or any weakening of the commitments above — in particular the commitments that nothing is written to the visitor’s device and that no visitor identifier is stored. For material changes we will post the updated version on this page with a new "Last updated" date and notify you by email at least 30 days before it takes effect, so that you can remove the tag if you disagree.
15. Contact
For any question under this DPA, to request a signed copy, or to send us an instruction, email support@tobecited.com. tobecited is operated from Spain (European Union); the operator’s legal identification details are available on request.