Skip to main content

Privacy

Data processing agreement

Email privacy@truestat.io from the address on your account, saying which entity should be named as controller.

Not available as a self-serve download yet. Request one by email and we will send it; the online signing flow is being built.

How to get one

Email privacy@truestat.io from the address on your account, saying which entity should be named as controller. You will get a DPA to sign.

There is no charge and it does not depend on your plan.

What it covers

The standard shape:

  • You are the controller; Codivion, LLC is the processor.

  • We process only on your documented instructions.

  • Confidentiality obligations on everyone with access.

  • The security measures in place.

  • Sub-processors, listed, with notice before any change.

  • Assistance with data subject requests, within the limits described in GDPR — the honest limit being that there is no individually identifiable data to produce.

  • Deletion or return of data on termination.

  • Audit and information rights.

  • Standard Contractual Clauses where a transfer needs them.

Sub-processors

Sub-processorWhat it holdsRegion
SupabaseYour analytics data, your account, your sitesEU (Frankfurt, eu-central-1)
StripeBilling details. Never analytics data.Global, EU processing for EU customers

Our hosting provider serves the application and terminates HTTPS. It does not store analytics data.

You will be told before this list changes.

What you can hand your legal team meanwhile

If a review is blocking and you need something before the DPA arrives, these three pages are written to be read by counsel:

The question that usually decides a review is whether the default sets a cookie. It does, and Do you need a cookie banner? is the page that answers it without hedging.

Was this page helpful?

Last updated August 28, 2026