Legal

Data Processing Agreement

Last updated September 16, 2026

This agreement applies automatically to every Spectry customer as part of our terms — you do not need to sign anything to be covered by it. If your organisation requires a counter-signed copy, email gdpr@spectry.io and we will return one.

This Data Processing Agreement forms part of the agreement between Plexcell Media and the Customer for the provision of the Spectry services. Where this agreement conflicts with the main agreement on the subject of personal data processing, this agreement prevails.

1. Parties

Processor: Plexcell Media, trading as Spectry, Business ID 2493526-5, Finland. Data protection contact: gdpr@spectry.io.

Controller: the Customer identified in the Agreement.

2. Roles of the parties

The Customer is the controller of Customer Personal Data. Spectry is the processor.

The Customer determines the purposes and means of processing: which of its websites or applications the services are deployed on, which features are enabled, what data is captured, what retention period applies, and on what lawful basis the processing rests. Each party is independently responsible for compliance with its own obligations under the GDPR.

Spectry acts as a controller in its own right only in respect of its own account, authentication, billing and service-communication data. That processing is governed by our privacy notice, not by this agreement.

3. Scope and instructions

3.1 Spectry processes Customer Personal Data only on the Customer's documented instructions, including in relation to transfers to a third country, unless required to do otherwise by Union or Member State law. Where such a legal requirement applies, Spectry informs the Customer before processing, unless that law prohibits it on important grounds of public interest.

3.2 The Agreement, this agreement, and the Customer's configuration of the services through its account together constitute the Customer's documented instructions. Configuration choices — which features are enabled, which elements are masked or excluded from capture, which retention period applies, which custom events and properties are sent — are instructions.

3.3 Spectry informs the Customer if, in its opinion, an instruction infringes applicable data protection law, and may suspend the affected processing until the instruction is withdrawn, amended or confirmed.

3.4 The Customer is responsible for:

  • establishing and maintaining a lawful basis for the processing, and obtaining and managing consent where required, including under the ePrivacy rules governing access to information stored on a visitor's device;
  • providing the transparency information required by Articles 13 and 14 to its own data subjects;
  • determining what data is captured, and in particular applying the masking and exclusion controls described in Annex II to any element of its pages that renders personal data;
  • not deliberately transmitting special categories of personal data under Article 9, or data relating to criminal convictions under Article 10, to the services.

4. Confidentiality

Spectry ensures that persons authorised to process Customer Personal Data are bound by an appropriate obligation of confidentiality. Access is limited to those who require it to provide, secure or support the services.

5. Security

Spectry implements appropriate technical and organisational measures as required by Article 32. Those measures are described in Annex II and may be updated as the services evolve, provided the overall level of protection is not materially reduced during the term.

6. Sub-processors

6.1 The Customer grants Spectry general written authorisation to engage sub-processors, subject to this clause. Those engaged at the date of this agreement are listed in Annex III.

6.2 Spectry gives the Customer at least 30 days' notice before adding or replacing a sub-processor, by the mechanism identified in Annex III.

6.3 The Customer may object on reasonable data-protection grounds within the notice period. The parties will discuss the objection in good faith. If it cannot be resolved, the Customer may terminate the affected part of the services without penalty, with a pro-rata refund of prepaid fees for the unused period.

6.4 Spectry imposes on each sub-processor data protection obligations no less protective than those in this agreement, and remains fully liable to the Customer for a sub-processor's performance.

7. Assistance with data subject rights

Taking into account the nature of the processing, Spectry assists the Customer by appropriate technical and organisational measures in fulfilling its obligation to respond to requests under Chapter III of the GDPR. The services include functionality allowing the Customer to service such requests directly:

  • Access and portability (Articles 15 and 20) — a request produces a structured, machine-readable export of the data held for an identified data subject.
  • Erasure (Article 17) — a request removes that data subject's records across all stores in which they are held, including analytics events and sessions, heatmap interaction data, session replay index records and the underlying recordings in object storage, survey and opt-in records, and the relational database.
  • Rectification and restriction (Articles 16 and 18) — supported through the Customer's administrative access to its account.

Where a data subject contacts Spectry directly, we refer them to the Customer and notify the Customer without undue delay. We do not respond to the substance of the request unless instructed. Assistance is provided at no additional charge, except where a request is manifestly unfounded, excessive or repetitive.

8. Personal data breach

Spectry notifies the Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data. The notification describes, to the extent known, the nature of the breach including the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed, and a contact point. Where the information cannot be provided at once it is provided in phases without undue further delay.

Spectry assists the Customer in meeting its own obligations under Articles 33 and 34. Notification of a breach is not an acknowledgement of fault or liability.

9. Impact assessments

Spectry assists the Customer with data protection impact assessments under Article 35 and prior consultation under Article 36. We maintain our own impact assessment covering session replay and behavioural analytics, and make a summary available on request.

10. Deletion and return

During the term, Customer Personal Data is retained in accordance with the retention period applicable to the Customer's plan and deleted automatically on expiry of that period. On termination, Spectry deletes Customer Personal Data, or returns it at the Customer's election, and deletes existing copies, unless law requires continued storage. Data held in backups is deleted on the ordinary backup expiry cycle rather than immediately, and is not restored to active processing after termination.

11. Audits

Spectry makes available the information necessary to demonstrate compliance with Article 28, including this agreement, Annex II, Annex III and our retention periods. Where that documentation does not reasonably satisfy the Customer, the Customer may conduct an audit, subject to: no more than once in any twelve month period, unless required by a supervisory authority or following a personal data breach; at least 30 days' written notice; conducted during normal business hours and so as not to disrupt operations; an auditor bound by confidentiality who is not a competitor of Spectry; and the Customer bearing its own and Spectry's reasonable costs.

12. International transfers

Customer Personal Data is stored and processed within the European Union. Where a sub-processor's processing involves a transfer outside the EEA, that transfer is governed by the Standard Contractual Clauses adopted by the European Commission in Implementing Decision (EU) 2021/914, or another valid mechanism under Chapter V. Annex III identifies the limited circumstances in which processing may occur outside the EEA.

13. Liability, term and governing law

Each party's liability under this agreement is subject to the limitations and exclusions of liability in the Agreement. This agreement takes effect when the Agreement takes effect and continues for as long as Spectry processes Customer Personal Data; clauses which by their nature should survive termination do so.

This agreement is governed by the laws of Finland and the courts of Finland have jurisdiction, unless the Agreement specifies otherwise. This does not deprive a data subject of the protection of mandatory provisions of the law of their habitual residence.

Annex I — Details of the processing

Subject matter. Provision of the Spectry analytics, experimentation, session replay, survey, feedback and lead-capture services.

Duration. The term of the Agreement, plus the applicable retention period.

Nature and purpose. Collection, recording, storage, structuring, analysis, aggregation and deletion of end-user interaction data, to provide the Customer with analytics, conversion optimisation, experimentation results, qualitative feedback and lead capture.

Categories of data subjects. Visitors to and users of the Customer's websites and applications; the Customer's own personnel who hold Spectry accounts.

Categories of personal data

CategoryDetail
Pseudonymous identifiers Randomly generated session and visitor identifiers, scoped to a single Customer site
Customer-supplied identifiers Where the Customer uses the identify function, the user identifier and any attributes it chooses to send
Technical and device data Browser, operating system, device type, screen dimensions, referring URL, approximate geographic region derived at request time
Behavioural data Page views, navigation paths, clicks and interaction events, scroll depth, custom events defined by the Customer, performance metrics
Session recordings Reconstructions of page interaction captured through session replay, subject to the masking controls in Annex II
Survey and feedback responses Responses submitted to surveys and feedback widgets configured by the Customer
Lead capture data Contact details, typically an email address, submitted through opt-in forms configured by the Customer

Data expressly not collected

Spectry does not store visitor IP addresses. An IP address is used transiently to resolve an approximate geographic region and is then discarded; it is not written to any analytics store, log or backup.

Special categories. The services are not designed for, and the Customer is instructed not to submit, special categories of personal data under Article 9 or data relating to criminal convictions under Article 10.

Annex II — Technical and organisational measures

The measures required by Article 32 are set out on our security measures page, incorporated into this agreement by reference.

Annex III — Sub-processors

The sub-processors engaged by Spectry are set out on our sub-processors page, incorporated into this agreement by reference. Notice of changes under clause 6.2 is given by email to the notification list described on that page.