Trust & security
Webcounter.ca Data Processing Agreement
Version 2026-08-06-1 · effective when the Controller accepts Terms version 2026-08-06-1 or later
This Data Processing Agreement (the “DPA”) is between the Webcounter.ca account holder (the “Controller”) and guardianmesh Inc., which operates Webcounter.ca (the “Processor”). It forms part of the Terms of Service whenever the Processor handles visitor personal data for the Controller. Accepting the Terms also accepts this DPA; no separate signature or checkbox is required.
Controller and processor roles
The Controller chooses the sites, analytics purposes, lawful basis, settings, and response to visitors. The Processor handles visitor personal data only to provide the configured service under the Controller’s documented instructions. guardianmesh Inc. separately acts as controller for account-holder information used to operate and secure Webcounter.ca, as described in the Privacy Notice.
1. Definitions and precedence
“Personal Data”, “Processing”, “Controller”, “Processor”, “Subprocessor”, and “Data Subject” have their meanings under applicable data-protection law. “Services” means the Webcounter.ca analytics, reporting, export, deletion, and uptime features configured by the Controller. This DPA controls if it conflicts with the Terms about Controller Personal Data. A mandatory transfer instrument controls over both where it conflicts.
2. Processing details
| Subject and purpose | Receive analytics events from the Controller’s sites; derive site-scoped identifiers and coarse location; aggregate and report visits; apply consent, retention, export, and deletion settings; and protect the Services. |
|---|---|
| Duration | While the account or site is active, followed by the 30-day recovery and 14-day backup-expiry periods on the data-retention page. |
| Data subjects | Visitors to the Controller’s tracked sites and authorised users whose activity is included in site analytics. |
| Personal data | Page, referrer, event, device, browser, and coarse-location signals; a keyed daily identifier derived temporarily from network address and user agent; and, after consent in optional cookie mode, a random first-party identifier re-keyed per site. The collection contract prohibits directly identifying fields, credentials, message contents, financial data, and health data. |
| Frequency | When the installed snippet sends events and when the Controller starts reporting, export, or deletion operations. |
3. Documented instructions
The Terms, this DPA, supported site settings, and authenticated requests form the Controller’s documented instructions. The Processor will follow those instructions, including for international transfers, unless the law requires other processing. Where permitted, the Processor will notify the Controller before legally required processing and will promptly report any instruction it reasonably believes violates data-protection law.
4. Confidentiality and security
The Processor limits access to people who need it to operate the Services and requires confidentiality. The security page describes its safeguards, including access control, hashed credentials and API keys, optional account MFA, HTTPS and HSTS, site-scoped identifiers, encrypted and restore-tested backups, tenant isolation, and limited retention. Measures may change without materially reducing overall protection.
5. Subprocessors
The Controller generally authorizes the subprocessors listed in the Privacy Notice. The Processor remains responsible where required by law and imposes suitable data-protection duties on each provider. At least 30 days before a new subprocessor receives Controller Personal Data, the Processor will email the verified account owner and update the public list. The Controller may object on reasonable data-protection grounds. If the objection cannot be resolved, the Controller may stop the affected processing and delete the affected site or account before access begins.
6. Data-subject requests
The Processor will reasonably assist with access, correction, deletion, objection, restriction, and portability requests through dashboard export and deletion tools and privacy@webcounter.ca. A request received directly about Controller Personal Data will be referred to the Controller. The Processor will not answer for the Controller unless instructed or legally required.
7. Security incidents
The Processor will notify the Controller without undue delay after learning of a confirmed breach affecting Controller Personal Data. As details become available, the notice will describe the incident, affected data and people, likely consequences, containment, remediation, and a contact. The Processor will reasonably assist with notification and investigation duties. Notice does not admit fault.
8. Compliance assistance
Using the information available to it, the Processor will reasonably assist with security and data-protection impact assessments, regulator consultations, and compliance records. The Controller remains responsible for lawful use, visitor notices, its legal basis, required consent, and data-subject rights.
9. Return and deletion
The Controller may export supported analytics before deletion. Deleting an account or site starts the published process: active data remains recoverable for 30 days, verified purge then removes it, and encrypted backups expire within another 14 days. This creates a maximum expected erasure period of 44 days. Data retained because the law requires it will be isolated from further service processing.
10. Audit information and inspections
On reasonable written request, no more than once in a 12-month period, the Processor will provide information needed to demonstrate compliance, starting with public documentation and a written remote review. Additional audits are allowed after a credible breach, on a regulator’s instruction, or when remote review cannot resolve a material concern. Where circumstances permit, audits require 30 days’ notice, must protect other customers and sensitive security information, and occur during normal business hours. The Controller pays unless the audit identifies a material Processor breach.
11. International transfers
The Services store and process Controller Personal Data in Canada. Sending data from outside Canada is a transfer to Canada. The parties rely on an applicable adequacy decision where it provides a lawful basis. Otherwise, they incorporate the European Commission’s 2021 Standard Contractual Clauses, Module Two (controller to processor): the Controller is exporter, guardianmesh Inc. is importer, Canada is destination, this DPA supplies Annexes I and II, and the optional docking clause applies. The UK International Data Transfer Addendum applies to restricted UK transfers. Swiss transfers adapt references to the Swiss Federal Act on Data Protection and competent authority. The Processor will provide reasonable transfer-assessment information and report if it can no longer meet the safeguard.
12. Government access
The Processor verifies the authority behind government and legal demands, challenges overbroad demands where reasonably possible, and discloses only what the law requires. It will notify the Controller before disclosure unless prohibited or prevented by an imminent safety risk, and will seek permission to give more information when notice is restricted. It provides no standing or bulk access.
13. Liability
Each party is responsible for damage caused by its breach of this DPA and for its own liability under data-protection law. The Terms’ limits and exclusions apply to contractual DPA claims as far as the law allows. This DPA does not exclude data-subject rights, regulatory powers, or liability that cannot legally be limited.
14. Governing law and jurisdiction
The laws of Ontario and the federal laws of Canada applicable there govern this DPA. The courts of Ontario have non-exclusive jurisdiction, subject to mandatory rights under applicable law and the forum terms of an incorporated transfer instrument.
15. Term and termination
This DPA begins when the Controller accepts the Terms version shown above and continues while the Processor handles Controller Personal Data. It ends after the deletion required by section 9, except for provisions that must survive. Closing the account does not remove obligations that arose before termination.
Questions about this DPA may be sent to privacy@webcounter.ca.