Not available as a self-serve download yet. Request one by email and we will send it; the online signing flow is being built.
How to get one
Email privacy@truestat.io from the address on your account, saying which entity should be named as controller. You will get a DPA to sign.
There is no charge and it does not depend on your plan.
What it covers
The standard shape:
You are the controller; Codivion, LLC is the processor.
We process only on your documented instructions.
Confidentiality obligations on everyone with access.
The security measures in place.
Sub-processors, listed, with notice before any change.
Assistance with data subject requests, within the limits described in GDPR — the honest limit being that there is no individually identifiable data to produce.
Deletion or return of data on termination.
Audit and information rights.
Standard Contractual Clauses where a transfer needs them.
Sub-processors
| Sub-processor | What it holds | Region |
| Supabase | Your analytics data, your account, your sites | EU (Frankfurt, eu-central-1) |
| Stripe | Billing details. Never analytics data. | Global, EU processing for EU customers |
Our hosting provider serves the application and terminates HTTPS. It does not store analytics data.
You will be told before this list changes.
What you can hand your legal team meanwhile
If a review is blocking and you need something before the DPA arrives, these three pages are written to be read by counsel:
What we store, and what we don't — the complete field list
How visitors are counted — the exact identity mechanism on each mode, including what is deleted and when
GDPR — roles, legal bases, and the data subject request position
The question that usually decides a review is whether the default sets a cookie. It does, and Do you need a cookie banner? is the page that answers it without hedging.