Data Processing Agreement
Last updated: June 9, 2026
1. Parties and Scope
This Data Processing Agreement ("DPA") is entered into between the client ("Business", "Controller") and Triumph Interactive, Inc. ("Service Provider", "Processor"). This DPA supplements the Triumph Analytics Terms of Service and applies to all personal information processed by Triumph Interactive, Inc. on behalf of the Business through the Triumph Analytics platform.
2. Definitions
- "Personal Information" has the meaning given in the California Consumer Privacy Act (CCPA), Cal. Civ. Code 1798.140(v)
- "Business" means the CCPA-defined "business" that determines the purposes and means of processing personal information
- "Service Provider" means the CCPA-defined "service provider" that processes personal information on behalf of the Business
- "Consumer" means a California resident whose personal information is processed
3. Role of Triumph Interactive, Inc.
Triumph Interactive, Inc. acts as a Service Provider under the CCPA. We process personal information solely on behalf of the Business, pursuant to the Business's instructions, and for the specific business purpose of providing web analytics services. We do not process personal information for our own commercial purposes.
4. Service Provider Obligations
Triumph Interactive, Inc. agrees to the following obligations:
- Process personal information only as instructed by the Business and as necessary to provide analytics services
- Not sell personal information received from the Business
- Not retain, use, or disclose personal information for any purpose other than providing the analytics service
- Not retain, use, or disclose personal information outside of the direct business relationship between the parties
- Not combine personal information received from the Business with personal information from other sources, except as permitted by the CCPA
- Notify the Business if we determine we can no longer meet our obligations as a Service Provider
- Allow the Business to take reasonable steps to stop and remediate unauthorized use of personal information
5. Consumer Rights Cooperation
Triumph Interactive, Inc. will cooperate with the Business's obligation to respond to consumer rights requests under the CCPA:
- Right to Know: We provide a Visitor Data Access API that allows the Business to retrieve all personal information associated with a visitor ID
- Right to Delete: We provide a Visitor Data Deletion API that submits a row-level deletion request for events and identity records associated with a visitor. Its outcome against compressed data has not been verified. Aggregated, de-identified data that cannot be re-associated with a consumer is exempt from deletion
- Right to Opt-Out: Our platform honors Global Privacy Control (GPC) signals, which automatically reduce data collection for visitors who send the signal
- Data Export: We provide CSV, Excel, JSON, and API export of available analytics data through supported features while the account and data remain accessible, subject to plan restrictions and the 100,000-row cap on raw JSON export
6. Data Categories and Processing
The following categories of personal information are processed:
- Identifiers: Visitor ID (cookie-based), IP address (for geolocation), email hash (if provided by Business)
- Internet Activity: Pages visited, referrer URLs, on-site search terms, click events, scroll depth
- Geolocation: Country and city derived from IP address lookup
- Device Information: Browser, operating system, screen resolution, device type, language
Processing purpose: Generating web analytics reports, attribution analysis, conversion tracking, and aggregate traffic insights.
7. Subprocessors
Triumph Interactive, Inc. uses the following subprocessors:
| Subprocessor | Purpose | Location |
|---|---|---|
| Amazon Web Services (AWS) | Application hosting, networking, caching (ElastiCache), load balancing, and (after migration) self-hosted TimescaleDB HA |
We will notify the Business before adding or replacing a subprocessor. The Business may object to a new subprocessor within 30 days of notification.
8. Data Security
Triumph Interactive, Inc. implements reasonable security measures including:
- Encryption in transit (TLS 1.2+) and at rest (AES-256)
- Network isolation via AWS VPC and security groups
- BCrypt password hashing for user credentials
- Rate limiting on all API endpoints
- Automated database backups with point-in-time recovery
- High-availability database configuration with automated failover
- Infrastructure monitoring with CloudWatch alarms
9. Data Breach Notification
In the event of a data breach affecting the Business's personal information, Triumph Interactive, Inc. will notify the Business within 72 hours of becoming aware of the breach. Notification will include the nature of the breach, categories and approximate number of records affected, likely consequences, and measures taken to address the breach.
10. Data Deletion on Termination
Following termination of the service agreement, Triumph Interactive, Inc. runs post-cancellation analytics-data cleanup after 90 days. The cleanup submits row-level deletion operations for events and visitor identities; its outcome against compressed data has not been verified. Before termination, the Business may request export of available analytics data through supported features while the account and data remain accessible, subject to plan restrictions and the 100,000-row cap on raw JSON export. After deletion, Triumph Interactive, Inc. will certify in writing that all personal information has been deleted or returned.
11. Audit Rights
Triumph Interactive, Inc. will make available to the Business all information necessary to demonstrate compliance with this DPA and the CCPA service provider requirements. The Business may audit Triumph Interactive, Inc.'s compliance with this DPA once per year with 30 days' written notice.
12. Contact
For questions about this DPA or to request a signed copy, contact us at our contact form.